Security Basics mailing list archives

Re: recommendations for centrally managed corporate antivirus solution


From: "Jon R. Kibler" <Jon.Kibler () aset com>
Date: Tue, 19 Feb 2008 15:26:05 -0500

illuminaeti () gmail com wrote:
Hi list

On the different networks I manage, I've been using Symantec corporate since version 7. I've never had any major issues with it until now. Version 11, now called "Symantec endpoint Protection" requires IIS and either MS SQL or the symantec embedded database. I installed a copy on a test server and it just about crippled it. Network access from clients was incredibly slow and processor use was hitting %100. I've heard the same comments from a collegue who installed it on a new server at the customer's request. The file server was virtually unusable even before the client was installed on the workstation. Also the new GUI is just plain awful. I don't have the time or resources to tweak settings to get better performance out of the AV. I've heard good things about NOD32, Sophos and Kaspersky. I've started looking around and of course, every website I visit tells me the software they sell is the best in the universe.
So, looking for real answers from real users, I thought I'd ask you all about your experience, positive or negative, 
with various corporate antivirus software.

Thanks in advance.

IMHO, for a large organization, nothing will touch Sophos. It has one of
the fastest updates, is easy to install, runs on just about everything
(Windows, Mac, Linux, etc.), it has a very low overhead, catches just
about everything, and has perhaps the best dashboard in the industry.
It also has fantastic support for roaming users. I have also found that
the latest version has essentially eliminated the need for SpyBot and
similar anti-spyware. The only thing I have found recently that Sophos
does not catch that SpyBot does catch are some tracking cookies.

Another advantage of Sophos is that with a corporate license, your users
can install it on their home computers for free. The only caveat is that
YOU are responsible for supporting their use. (Sophos only sells to
the corporate customer, so they do not maintain support for non-technical
user's issues.)

It also does not take a lot of horsepower to run. I have once customer
that is running the enterprise console on a 10+ year old HP box and it
has great performance under W2K3. That box supports several hundred users.
Also, the product is entirely self-contained. It does not require any
other products (other than a standard minimal O/S install) to run.

The latest version also comes with a great centrally managed firewall
and NAC solution -- and these can be installed independently of the AV.

Finally, I have never seen tech support for ANY product that is anything
close to the quality of support from Sophos. There is not the hassle of
going through multiple layers of support -- you ALWAYS get to speak
directly to the experts. Plus, the have fantastic remote or on-site
training available.

DISCLOSURE: I do NOT work for Sophos, do NOT sell their product, or have
ANY other type of relationship with Sophos. I just find it to be a
fantastic product.

Jon Kibler
--
Jon R. Kibler
Chief Technical Officer
Advanced Systems Engineering Technology, Inc.
Charleston, SC  USA
o: 843-849-8214
m: 843-224-2494




==================================================
Filtered by: TRUSTEM.COM's Email Filtering Service
http://www.trustem.com/
No Spam. No Viruses. Just Good Clean Email.


Current thread: