Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Sophos Free Mac Antivirus Home Edition Hangs Huawei MT-841 Modem

Hi all,

Impressed with Sophos Antivirus for Android, I installed  Free Mac  Antivirus Home Edition of Sophos on my MBP.

Remarkably I have come acrross an interesting issue,

My ADSL 2+ Huawei modem hangs cause of Anti Virus !!

Before some one says to check my networkk set up, let me clear some things about me,

I am a full time developer / reverse engineer and Red Hat Certified , so I have some Networking knowledge to come to this conclusion.

My Network Connection is as follows,

ISP --> Huawei ADSL 2+  MT841 Modem/Router (DHCP disabled & Firewall disabled) --> ASUS N10+ (DDWRT - DHCP enabled ) --> iMac and Macbook

My Setup -

1. Free Mac  Antivirus Home Edition of Sophos installed on my Mac Book .

2. My Macbook has  OSX Lion 10.7.4 with internal firewall and Little snitch  enabled.

Issue :

1. The modem hangs in 1 - 2 hrs after the boot of Mac Book and Anti Virus running.

Troubleshooting Followed :

I followed the following troubleshooting methodology for two days before arriving at the conclusion.

1. Checked by removing the router between the modem and MBP and connected directly to modem - issue occurs in 1-2 hrs.

2.  Disabled / Enabled DHCP servers on modem and router alternatively - issue not resolved.

3. Reset / Restored default settings in modem - issue occurs back in 1-2 hrs.

Temporary Fix :

1 . Modem restarted , the issue occues after 1-2 Hrs.

Permanent Solution :

1. Uninstalled  Free Mac  Antivirus Home Edition . - Modem works perfect .

Observations :

1. My Huawei MT 841 modem has been working great for 7 years with no issues so far . But  I could find a 2008  thread on the same modem having same  issue with Trend Micro Internet security  on a  Windows OS. That was an official bug in Trend Micro AV related to global threat sense technology in it.

2 . Free Mac  Antivirus Home Edition of Sophos had a similar Threat sense technology connecting to global servers, I wonder whether it causes my modem to hang.

Conclusion :

Sophos products are great no doubt on that, Free Mac  Antivirus Home Edition of Sophos looked promising it even detected windows virus from the parallels desktop VM. But I cannot continue using it unless the bug which causes my modem to hang gets resolved. It would be intresting to know how the Antivirus could cause a modem across the router to hang.

Looking for answers from Sophos support. I have mailed them, will soon post their reply.

Thanks.

:1007803


This thread was automatically locked due to age.
Parents
  • Hi Andrew ,

    Thanks for your heads up on the DNS caching, I dug some info and found some interesting information.

    1. All most all Modems/Routers made by  GlobespanVirata using ATMos chip and ISOS SW has/had DNS caching issues cause of low memory , atleast till the one made till 2005 (as that of my Huawei MT 841).

    I had no option to disable DNS caching, so I disabled the whole DNS Relay system and made my DD-WRT Router (which has virtually unlimited cache) as the local DNS server.

    2. I installed Sophos Free Mac Antivirus now and There is absolutely no issues. So problem resolved !!

    Hi Bob Cook,

    Yes. Issue was definetly with my Modem,

    But I had been using it  extensively for 7 years (most of the time 24/7 connecting multiple machines) but the issue arised only now , Might be cause like you said Sophos using DNS REQ with upper limit of the standard size and it pushed my modem to the maximum it could  handle (I am infact very glad of it !!) .

    The reason I am telling this is, My search  told me, there are number of  modems/routers outthere with the same DNS caching issue. Atleast here in India these modems are distributed widely by a country level ISP having a huge market share (you know the population ). So every one of them who have a Mac and try to use Free Sophos AV would face similar issue as mine. I am 100% certain that their modem would hang, there by by resorting to un-installing the Sophos AV.

    Therefore I suggest, Including this as a known issue in the document cautioning  the users to fix their modems before installing the AV or better running a small tests to asses the DNS caching ability of the user's modem/router. Just a thought.

    I am really impressesd with the support you guys brought in this open forum, I appreciate it. I will use Sophos AV and surely recommend to others.

    Thanks.

    :1007847
Reply
  • Hi Andrew ,

    Thanks for your heads up on the DNS caching, I dug some info and found some interesting information.

    1. All most all Modems/Routers made by  GlobespanVirata using ATMos chip and ISOS SW has/had DNS caching issues cause of low memory , atleast till the one made till 2005 (as that of my Huawei MT 841).

    I had no option to disable DNS caching, so I disabled the whole DNS Relay system and made my DD-WRT Router (which has virtually unlimited cache) as the local DNS server.

    2. I installed Sophos Free Mac Antivirus now and There is absolutely no issues. So problem resolved !!

    Hi Bob Cook,

    Yes. Issue was definetly with my Modem,

    But I had been using it  extensively for 7 years (most of the time 24/7 connecting multiple machines) but the issue arised only now , Might be cause like you said Sophos using DNS REQ with upper limit of the standard size and it pushed my modem to the maximum it could  handle (I am infact very glad of it !!) .

    The reason I am telling this is, My search  told me, there are number of  modems/routers outthere with the same DNS caching issue. Atleast here in India these modems are distributed widely by a country level ISP having a huge market share (you know the population ). So every one of them who have a Mac and try to use Free Sophos AV would face similar issue as mine. I am 100% certain that their modem would hang, there by by resorting to un-installing the Sophos AV.

    Therefore I suggest, Including this as a known issue in the document cautioning  the users to fix their modems before installing the AV or better running a small tests to asses the DNS caching ability of the user's modem/router. Just a thought.

    I am really impressesd with the support you guys brought in this open forum, I appreciate it. I will use Sophos AV and surely recommend to others.

    Thanks.

    :1007847
Children
No Data