RE: [SPAM] - RE: recommendations for centrally managed corporate antivirus solution - Bayesian Filter detected spam





You can point any pc in EPO to use the McAfee http site for DAT updates
as a failover if the pc is not on your LAN for updates. This is great
for laptops.

Greg
-----Original Message-----
From: listbounce@xxxxxxxxxxxxxxxxx [mailto:listbounce@xxxxxxxxxxxxxxxxx]
On Behalf Of Albert Gonzalez
Sent: Friday, February 15, 2008 9:49 PM
To: Secure This; illuminaeti@xxxxxxxxx
Cc: security-basics@xxxxxxxxxxxxxxxxx
Subject: [SPAM] - RE: recommendations for centrally managed corporate
antivirus solution - Bayesian Filter detected spam

We currently use McAfee and their ePo server. We manage roughly 12000~
clients. The reporting makes the higher ups happy and is generally fast
and smooth with custom granular control. Unfortunately it does not allow
updates via the internet, only via our corp mgmt server(s). We just
rolled out their HIPS solution, and all it took was a flick of the
switch and as clients check in (often right? :)) the agent was deployed.
I am happy with the implementation, although this and symantec are the
only ones I have seen (corp deployments) I have not had the chance to do
any bakeoffs as these are existing infrastructures.

Opinions and experiences help, but every environment is different and
highly depends on what you want to report on. It all boils down to
reporting and that "warm fuzzy" feeling.

Thanks,
- Albert

-- Sent from my HTC8600.
Success comes to the person who does today, what you're thinking of
doing tomorrow.

-----Original Message-----
From: Secure This <lists@xxxxxxxxxxxxxx>
Sent: Friday, February 15, 2008 8:43 AM
To: illuminaeti@xxxxxxxxx
Cc: security-basics@xxxxxxxxxxxxxxxxx
Subject: Re: recommendations for centrally managed corporate antivirus
solution

McAfee EPO is the main player in the large corporate sector in the
Europe from my experience of around 50 large companies. Most seem happy
enough with it and renew their contracts. Works well across multi office

companies.
Hi list

On the different networks I manage, I've been using Symantec corporate
since version 7. I've never had any major issues with it until now.

Version 11, now called "Symantec endpoint Protection" requires IIS and
either MS SQL or the symantec embedded database. I installed a copy on a
test server and it just about crippled it. Network access from clients
was incredibly slow and processor use was hitting %100. I've heard the
same comments from a collegue who installed it on a new server at the
customer's request. The file server was virtually unusable even before
the client was installed on the workstation. Also the new GUI is just
plain awful.

I don't have the time or resources to tweak settings to get better
performance out of the AV.
I've heard good things about NOD32, Sophos and Kaspersky. I've
started looking around and of course, every website I visit tells me the
software they sell is the best in the universe.

So, looking for real answers from real users, I thought I'd ask you
all about your experience, positive or negative, with various corporate
antivirus software.

Thanks in advance.






Relevant Pages

  • RE: Welcome Screen changed to classic logon
    ... I have not seen any other recent reports of McAfee conflicting with other ... updates outside of updating to IE7 causing the McAfee updater to Fail. ... windows UI message and other new issues occurring after a system restore ... inplace upgrade/repair install of XP, the instructions can be found here: ...
    (microsoft.public.windowsupdate)
  • Re: Norton vs McAfee
    ... > | manually installing the software on all workstations, ... > pull the files from the McAfee FTP server and post the files to the ... > By pushing updates I get two results. ... > spreadsheet of all hits. ...
    (microsoft.public.security.virus)
  • Re: System locks up after updates
    ... but when I shut down and then reboot it locks up. ... Now to today's report :-) I followed your instructions to uninstall McAfee ... It did tell me that there were 3 windows updates, ... go ahead and install them - system said one wasn't installed - unnecessary. ...
    (microsoft.public.windowsupdate)
  • Re: Corrupt files in download -- cant install AV software
    ... each time McAfee tried to update ... it downloaded 12 updates. ... download files to my computer, ... to install it got to 57 percent and gave me the file is corrupt error. ...
    (alt.comp.anti-virus)
  • [Full-disclosure] EEYE: McAfee ePolicy Orchestrator Remote Compromise
    ... McAfee ePolicy Orchestrator Remote Compromise ... McAfee Common Management (EPO) Agent versions below version 3.5.5.438 ...
    (Full-Disclosure)