This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Sophos Endpoint Features

Hi,

i am currently working on sophos endpoint evaluation for a customer.. just want to ask this following questions.

1. is there a limitation on number of endpoints can be managed or accomodate by SEC?

2. is there any High availability or disaster recovery or replication procedure for the SEC?

3. Whats the content of the pattern update and size download in a day?

4. how does Sophos handle/manage offline endpoint?

5.How does Sophos handle and scans virtual machines?

any input is much appreciated. thanks in advance.

:35595


This thread was automatically locked due to age.
Parents
  • Hi,

    1. There is no hard limits, it's really constrained only by the resource the system runs on.  That being said the guidelines are 25K per console.  At 10K you should introduce message relays.

    2. VMWare/virtualization possible?  That would be the easiest method.  It really depends how quick you need to be running as:

    http://www.sophos.com/en-us/support/knowledgebase/27265.aspx

    might be enough?

    3. 8-10 ide files a day, 20K average so the daily updates are quite trivial.  As for product updates each month, well they can subscribe to a fixed package for 3 months.  They could even subscribe to an extended maint version, i.e.. 9.7 and that will reduce the monthly updates further as it is typically only data.

    4.  This can be answered in terms of management and updates.

    Management:

    If a managed client goes offline it will store messages locally until the point it is able to connect to the management server to deliver the messages.  So the messages will not be lost.   You can set up the communication method to operate over the internet also.  This might give you a few ideas: /search?q= 20971

    Updates:

    Continue to update from a secondary source of either Sophos or a web CID created in the companies own infrastructure.

    5. To ensure that schedule scans do not clash and consume too much resource, there is a virtualisation scan controller add on to enterprise console.

    http://www.sophos.com/en-us/support/documentation/virtualization-scan-controller.aspx#

    It's a little tricky to setup but will do the job.

    Regards,

    Jak

    :35599
Reply
  • Hi,

    1. There is no hard limits, it's really constrained only by the resource the system runs on.  That being said the guidelines are 25K per console.  At 10K you should introduce message relays.

    2. VMWare/virtualization possible?  That would be the easiest method.  It really depends how quick you need to be running as:

    http://www.sophos.com/en-us/support/knowledgebase/27265.aspx

    might be enough?

    3. 8-10 ide files a day, 20K average so the daily updates are quite trivial.  As for product updates each month, well they can subscribe to a fixed package for 3 months.  They could even subscribe to an extended maint version, i.e.. 9.7 and that will reduce the monthly updates further as it is typically only data.

    4.  This can be answered in terms of management and updates.

    Management:

    If a managed client goes offline it will store messages locally until the point it is able to connect to the management server to deliver the messages.  So the messages will not be lost.   You can set up the communication method to operate over the internet also.  This might give you a few ideas: /search?q= 20971

    Updates:

    Continue to update from a secondary source of either Sophos or a web CID created in the companies own infrastructure.

    5. To ensure that schedule scans do not clash and consume too much resource, there is a virtualisation scan controller add on to enterprise console.

    http://www.sophos.com/en-us/support/documentation/virtualization-scan-controller.aspx#

    It's a little tricky to setup but will do the job.

    Regards,

    Jak

    :35599
Children
No Data