This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Questions on Sophos Exceptions

Hello all,

I am new to this forum.

In looking at Endpoint Protection documentation I could not find some answers.

Currently running Endpoint 10.3 on both Windows 2003 and Windows 2012.

Also I am running in standalone mode here on specific servers.

Here are some questions.

1. When configuring Sophos exceptions, there are 2 places where I can configure. a) on-access b) on-demand and HIPS.

    I am configuring exceptions for Active Directory. I see in the on-demand section these settings are global and affect all scans.

    Does this mean I can configure in on-demand and this will also cover on-access scanning as well? Or do I need to configure

    both on-demand and on-access exclusions for this to work properly?

2. Lastly, Where is the location of the exclusions list? I have read they are held in machine.xml, but after adding them I do not see them in the xml file? Is this the correct file or are exclusions kept elsewhere? I have a large number of similar servers to deploy exceptions to and want to be able to stage exceptions per server type? I realize that there may be steps on service shut down to do before replacing files, but wondered if this type of automation has been done and where exceptions are stored.

Any help is appreciated.

David. 

:46443


This thread was automatically locked due to age.
Parents
  • Hello David,

    well, you sure have a good reason for running (several of) them standalone (though what this could be evades me for the moment).
    Anyway,
    1. on-demand and on-access settings are independent
    2. are you thinking of copying machine.xml? While it no longer contains SID values it's still machine-specific so copying from one machine to another might have unwanted effects. This being an XML file you could replace/update specific tags though (after stopping savservice).

    Christian
    :46447
Reply
  • Hello David,

    well, you sure have a good reason for running (several of) them standalone (though what this could be evades me for the moment).
    Anyway,
    1. on-demand and on-access settings are independent
    2. are you thinking of copying machine.xml? While it no longer contains SID values it's still machine-specific so copying from one machine to another might have unwanted effects. This being an XML file you could replace/update specific tags though (after stopping savservice).

    Christian
    :46447
Children
No Data