This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Best Practices for Sophos AV

Dear All

Thought I might be able to get a thread going here whereby we post our Sophos AV setup and configurations.   This way we might be able to see why others have implemented Sophos in a certain way and maybe understand better which policies need tweaking etc.    I am about to harmonise our 4 offices installations of Sophos so before I do that hopefully someone will notice something possibly wrong with my setup or offer advice on why it should be changed etc.

So here goes...

  • Sophos 9 running on a complete Windows environment synchronised with Active Directory.
  • Each Sophos server controls its own policies.  If I could configure one server for policies and push these policies out to the other sites that would be ideal, but I don't know if its possible and whether my branch office pc's would update correctly?
  • Workstations check for updates every 60 minutes
  • On Access scanning enabled on all workstations, behaviour = On Read
  • Remote scanning of files disabled
  • Auto cleanup of infected files, move to default location
  • Web scanning is 'As on access'
  • All Servers On Access scanning disabled, scheduled scans run each night at 9PM
  • HIPS enabled for notifications only.  Too many false positives for software updates IMO

We also use the Application Control and Device Control which (when working) helps us to nail down rogue apps!

If anyone has any recommendations for me to change I am all ears!

Cheers

:850


This thread was automatically locked due to age.
Parents
  • One domain or multiple domains? How are the offices connected - over WAN?

    Let me first try to understand your setup: each of the (four) servers synchronises a certain container in your AD or one of your domains (and it is not possible for whatever reasons that one server manages all the computers)? Guess it's either full synchronisation features or central policies but not both.

    • Checking for  updates every 10 minutes (no reason to set it higher and maybe I'll try 5)
    • On access read and write (since Conficker as I've already said, no complaints and no observable loss in performance)
    • remote files are scanned
    • auto cleanup and either block or delete (had some issues with rootkit items when move is selected)
    • (some of the) servers have also On Access enabled (some are running "alternate scanners", such things happen during an interregnum :smileywink:)
    • HIPS alert only. I know, the guys responsible for software updates could and should check in advance so it'd be possible to authorize the necessary programs before deployment but ...  (BTW: what is the difference between the checkbox  [On-Access scanning ...]->Scanning->Scanning Options/Scan for suspicous files (HIPS) and [HIPS runtime behavior ...]?

    Christian

    :853
Reply
  • One domain or multiple domains? How are the offices connected - over WAN?

    Let me first try to understand your setup: each of the (four) servers synchronises a certain container in your AD or one of your domains (and it is not possible for whatever reasons that one server manages all the computers)? Guess it's either full synchronisation features or central policies but not both.

    • Checking for  updates every 10 minutes (no reason to set it higher and maybe I'll try 5)
    • On access read and write (since Conficker as I've already said, no complaints and no observable loss in performance)
    • remote files are scanned
    • auto cleanup and either block or delete (had some issues with rootkit items when move is selected)
    • (some of the) servers have also On Access enabled (some are running "alternate scanners", such things happen during an interregnum :smileywink:)
    • HIPS alert only. I know, the guys responsible for software updates could and should check in advance so it'd be possible to authorize the necessary programs before deployment but ...  (BTW: what is the difference between the checkbox  [On-Access scanning ...]->Scanning->Scanning Options/Scan for suspicous files (HIPS) and [HIPS runtime behavior ...]?

    Christian

    :853
Children
No Data