thank you for the suggestion, but we have not enabled FW or NAC, just SAV. We wanted to ensure the product was deployed and working properly before enabling any advanced features.
Main Topics
Browse All Topicswe recently deployed sophos and are having performance issues on many machines. Users are complaining of slow performance across the board, specifically mentioning outlook (2003 and 2007), internet explorer, file explorer, visio.
User base is predominantly XP SP3, and a few Win7 Pro.
This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.
Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.
If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.
Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.
Access the answers to your technology questions today.
30-day free trial. Register in 60 seconds.
Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Try it out and discover for yourself.
30-day free trial. Register in 60 seconds.
Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.
What version of EM manager are you using? Are you updating from a server, or directly from the site? And, are you using the Sophos firewall along with the AV? I have had users complaing that the on-access scanning slowed them down considerably, especially if their scanning level is set to "extensive" and the "scanning inside archive files" option is checked. You will also want to check the on-demand extensions and exclusions and verify you are scanning only "controlled" extensions rather than the "scan all files" option.
sophos client version is 7.6.11
sophos management console is 3.1.0.2476
We are not use firewall or nac.
we are not using any "extensive" scan options, not scanning inside archives, not scanning all files.
We are continuing to work with sophos support to determine the root problem, but i thought it would be good to check with the EE community as well.
Thanks again.
performance problems seem to be worse on XP.
Have not received performance complaints from Win 7 users.
Sophos support recommneded making the following changes to our policy:
- Exclude PST and OST files
- Exclude Sysvol and Recycle folders
- Disable HIPS scanning
- Disable Adware/PUA scanning
- Disable remote file scanning
- Enable On Write scanning
I dont know that i'm comfortable with turning off protection to improve performance to a "tolerable" level...
They are essentially giving you the default values for SAV -- but I would recommend lowering the protection, and then upgrading the policy one option at a time to see which ones might be slowing you down.
I have had some lag problems with Sophos in the past as well and on some machines loaded Sophos to where it doesn't update from my EM server, but directly from the Sophos site using my download username/pass. You can't monitor that machine from your server, but it does have real-time protection and may speed things up.
@magicfarmer
Why is Sophos performance suffering more than other AV solutions? Are the additional features of sophos worth the performance hit, or should we pull sophos and select another vendor?
Avast was one vendor that provided top protection in our reviews, worked out of the box, and we received no reports of performance problems. It doesnt have the advanced features like firewall, nac, and application control, but these are coming built into win7 and server 2008r2. Avast also did not offer phone support, which is another reason we decided to pursue sophos. In the end though, support is much less important if the product works without fiddling.
I have had very good luck with Sophos, but I must admit I have had some sites where it didn't install (initially) as clean as I would like. Once up and running, however, I have found it to be the most effective on-access scanner. I had a site with a Vundo multiple office outbreak three weeks ago, with one site on Kapersky and one on Sophos. Not one of the Sophos machines was infected (everything went straight to quarantine) but four of of 15 Kapersky machines were hit.
And once you get NAC up and running you will really like the convenience of the interface. Of the functions they are recommending you initially disable, I think the HIPS is the only one you will want to make sure in enabled down the road. I use a variety of different applications for spyware/adware in addition to Sophos, so I don't have the Adware/PUA activated.
Keep me posted on your progress -- unfortunately I am very experienced in the trial-and-error phase with Sophos installations.
Business Accounts
Answer for Membership
by: wilsonm735Posted on 2009-09-29 at 10:17:55ID: 25451186
I would suggest disabling the Sophos Firewall on the client-side, if it is installed already.