SAV for NAS 5.2 Challenges
Hello SymTeam!
I have a few questions regarding the funtioning or SAV for NAS.
Background:
I have have a pair of Scan Engine servers configured to scan a pair of NetApp filers. It is expected that this setup will allow for load balancing and failover for scanning. Currently each Scan Engine server is scanning the same Filer even though both Filers are meant to be scanned. The second Filer is not being scanned at all. When an error is encountered the same error shows up on both Scan Engine servers.
1. I need some more info on how a Scan Engine pair work together.
a. Alerts are logged when a Scan Engine cannot scan a file (cause to be determined). The same error is being logged on both Scan Engine servers. I am GUESSING that when such an error does occur on one Scan Engine then it may ask the another Scan Engine to try to scan the file. This MAY BE why I am seeing the same errors for the same files across both Scan Engines. Can I get this functionality confirmed please?
2. I need more info on how the Scan Engines work with multiple NetApp Filers.
a. All the alerts/logs I observe I seem to focus on just ONE Filer IP – never across both Filer IPs. Is this normal?
c. Do the Filers automatically load balance across the two Scan Engine servers or are the Scan Engine servers listed in the NetApp console configured as a "primary" and "secondary"? If so, how do you set the second Scan Engine server to be a "secondary"? Can I get this functionality confirmed please?
From the NetApp, the current setup can be seen below:
Virus scanners(IP and Name) P/S Connect time (dd:hh:mm) Reqs Fails Curr. Reqs.
-------------------------------------------------------------------------------------------
203.15.191.118 \\ScanEngineServer1 Pri 06:16:59 391937 273 0
203.15.191.119 \\ScanEngineServer2 Pri 05:21:37 391936 295 0
3. I need more info on how the Scan Engines work with client PC Network AV scanning.
a. The current architecture implemented has both the Scan Engines and SEP clients setup to scan network files. This means that when a network file is accessed via a client PC, the Scan Engine(s) first scan the file – then, the PC SEP client will also attempt to scan the file.
This does not seem very efficient & doubles up on scanning that perhaps could be considered overkill. It is suggested in some knowledgebase articles that this could be a possible cause of the scanning errors I am observing, ie. because of a conflict between the Scan Engine & the local PC AV tool both trying to scan the file. Some articles recommend disabling the PC Network file AV scanning capabilities if Scan Engines are employed. Not sure if this can be done on a per share/UNC/Filer basis or not.
4. When can I get an admin guide for NetApp so I can see what commands are available?
Cheers,
Comments 2 Comments • Jump to latest comment
1) The Scan Engine's are not aware of eachother and do not communicate or share/pass any information between them. What is scanned and the Scan Engine it is scanned on is up to the filer. If the filer request a file be scanned by one Scan Engine then later the other Scan Engine, so you may see the same errors and log information between the two Scan Engines.
2) Each Scan Engine must be registered with each filer you wish it to scan files for, and each filer must have vscan configured and enabled.
3) I do not support or have indepth knowledge of the SEP product, however I do not believe you can disable network scanning based on UNC/filer basis.
4) NetApp would provide the command and manual for opperations with the filer software not Symantec.
I have attached the integration guide for Scan Engine for Network Attached Storage for your review as well as the Scan Engine Manuall (implemenetation guide).
From the NetApp Best Practices Guide
Cameron Mottus
Would you like to reply?
Login or Register to post your comment.