Wednesday 4 December 2013

Replacing McAfee VSE with MOVE MP AV


MOVE - McAfee Management for Optimized Virtual Environments
MP - Multi-Platform AV (requires McAfee agents on VMs)
AL - Agentless AV (no software required on VMs)
OSS - Offload Scan Server — provides offloaded scanning support for VMs
SVA - Security Virtual Appliance - delivered as an Open Virtualization Format package
VSE - VirusScan Enterprise 
HIPS - Host Intrusion Prevention

The difference between MOVE MP and AL:

• According to McAfee, there is no difference in performance
• MP supports ePO policies per VM or OU through McAfee agents; AL has only 1 policy per hypervisor
• MP is easier to install, configure and manage than AL
• AL requires dedicated networks/links between the SVA and target VMs
• On-screen pop-up notifications on client VMs are available with MP only
• AL can be deployed on VMware hypervisors only
• AL requires 1 SVA per ESX host, while MP requires 1 or 2 OSS’s per cluster
• AL is slightly lighter; it may be beneficial to lose McAfee agents from VMs in order to achieve higher VM density

As access protection and buffer-overflow protection features are not included in MOVE AV, McAfee recommends deploying HIPS as an additional layer in order to get close to the security level offered by VSE. HIPS can be configured for minimal interference so it doesn’t impact VMs’ performances badly.

OSS VM(s) should not be hosted together with other resource-hungry VMs, so that they don’t compete for resources with important production systems. Each ESX cluster should have its own OSS server(s). It’s recommended to have 2 OSS servers per cluster. If there is more than 1 OSS per cluster, they should be hosted on separate hypervisors.

I could not get official advice or find any info on whether VSE would perform better in certain scenarios, e.g. on file servers, as it could take some time for a big file to be transferred from a host VM to the OSS for scanning. Lots of such files accessed simultaneously could negatively affect all VMs on the cluster. There is no info on how MOVE compares to VSE performance wise.

MOVE uses file caching to boost performances, and it’s available for both on-demand and on-access (real-time) scanning. The size of the cache and time to keep the items are configurable.

Officially, an OSS can manage/scan up to 450 hosts, but in reality probably between 100 and 250, depending how busy these VMs are. The current load of an OSS can be determined by monitoring the OSS server statistics, e.g. the values of Avg request process time and Avg request wait time (C:\Program Files (x86)\McAfee\MOVE AV Server>mvadm stats).

VMware on vShield:

vShield Endpoint improves performance by offloading virus-scanning activities from each virtual machine to a secure virtual appliance that has a virus-scanning engine, as well as the stored antivirus signatures. For antivirus and anti-malware functions, this architecture eliminates the software agent footprint in guest virtual machines, frees up system resources, improves performance and eliminates the risk of antivirus “storms” (overloaded resources during scheduled scans and signature updates). Because the secure virtual appliance - unlike a guest virtual machine – doesn’t go offline, it can continuously update antivirus signatures, giving uninterrupted protection to the virtual machines on the host. Also, new virtual machines (or existing virtual machines that went offline) are immediately protected with the most current antivirus signatures when they come online.

General guidelines (from the MOVE deployment guide):

The number of clients that can connect to a single Offload Scan Server depends on these factors:

• Server hardware
• Network availability
• Workload per client

The optimal configuration is different in every environment. The primary criteria for determining the optimal number of clients a single Offload Scan Server can support is the number of concurrent client scan requests. Performance degrades when it receives more concurrent scan requests than it is configured to handle.

The Offload Scan Server can handle a maximum of 3,000 concurrent active scan connections:

• Heartbeats
• Scan requests
• Server‑side cache requests

If the server has reached its maximum of 3,000 active connections, any new connection is accepted, but queued for handling until one of the 3,000 active connections completes. Each client has a maximum of six active connections to an Offload Scan Server (one connection for a heartbeat and five for scan and cache check requests), limiting the Offload Scan Server to effectively handle a maximum of 500 clients before the connections start to queue. You can increase the number of clients connected to a single Offload Scan Server if the number of concurrent scan requests does not exceed the configured Concurrent Scans value. If this value is exceeded, server performance begins to rapidly decline.


Getting info on MOVE clients and servers:





MOVE client and server policies:



Deploying MOVE clients:


More info:
McAfee in the Data Center -Optimized Security for Virtualization
McAfee MOVE Antivirus joins the vShield Endpoint Family
MOVE Antivirus 2.6 Known Issues
Release Notes - McAfee MOVE AntiVirus 2.6.0 Patch 1
Supported environments for MOVE on Microsoft Windows
To HIPS or not
What are the McAfee MOVE 2.x products?
What is vShield Endpoint?

19 comments:

  1. https://wwHello, dear
    It is an outstandingly lovely article and I am examined your blog. I am extraordinarily happy to scrutinize your blog in light of the way that your information extremely incredible I like it and love it. thankful to you such a lot of offer with us this profitable information and I have a comparative sort of .if you require any help this article is useful to you.thank you to such a degree. More Details…..(Mcafee.com/activate).
    w.mcafeecom.net/Activate/

    ReplyDelete
  2. If you have any kind of trouble in sending or receiving AOL mail or have any other AOL related issue and need some human help to get a solution. Contact AOL Phone Number

    ReplyDelete
  3. Need antivirus for your PC and laptop? We provides best antivirus software for mac, windows and many more. Call us and connect with the techies Mcafee UK | Mcafee Phone Number

    ReplyDelete
  4. We are provides a Quickbooks Support Phone Number. Our support team constitutes of highly skilled & trained technicians who have years of experience in handling technical defects. It doesn’t matter how complex the issues would be. Get it resolved, from our Support team. As they are available for you, 24*7. Whenever you face any trouble, feel free to contact Quickbooks helpline 800-901-6679.

    ReplyDelete
  5. Good article,Thank you for sharing valuable information. If you are facing any problem with netgear router can visit here Netgear Support UK

    ReplyDelete
  6. This blog is really very helpful but still if you have any issues with McAfee antivirus, then you can contact McAfee support UK.

    ReplyDelete
  7. The design of the website is really very attractive, if you need any help over the setup of Kaspersky connection not protected | Kaspersky antivirus update problem

    ReplyDelete
  8. I am really very much satisfied after reading this post. The writer has really great knowledge of grammar and vocabulary and hence not a single grammatical error is there.How to fix if yahoo mail does not work for Instagram?

    ReplyDelete
  9. Anyone can understand this post as every single sentence is written by using simple words. Grammar is also not that much difficult so anyone can understand this post.Netflix Error 1011

    ReplyDelete
  10. Do you want to know more and more about this topic then, you should read this topic. This post is written by a skilled writer who has a keen knowledge of writing. HOW TO TROUBLESHOOT ISSUE OF KASPERSKY NOT WORKING ON WINDOWS 10?

    ReplyDelete
  11. Bullguard is a trusted name in the cybersecurity market, the software has been providing the users with the best level of online security and while the user uses the internet also it provides all the other needed safety for the computer along with that the antivirus software is also known for working on the optimization of the performance of the system.What Are The Pros And Cons Associated With The Use Of Bullguard Premium Protection?

    ReplyDelete

  12. Antivirus software detects or perceives the viruses and malware and afterward ensuing to identifying the nearness of the virus and it works on expelling it from the PC framework. Antivirus works as a shield with an aim to remove the virus and to flush out any possible virus from infecting your PC in the future. TROUBLESHOOTING PROCEDURE FOLLOWED FOR FIXING KASPERSKY DATABASE UPDATE PROCESS STUCK :

    ReplyDelete

  13. AVG antivirus as we all know is advanced security software that has all the features included in its setup that is needed for the efficient security of the computers and devices from all types of viruses, malware, spyware Trojans, and viral attacks.The software is the best choice as it comes to its performance against all these elements. How to disable AVG antivirus components?

    ReplyDelete

  14. For troubleshooting, no connection error in Gmail the user should get the internet connection checked also the user should get the cache cleared from the browser also the date and time settings should be checked. The log-in credentials should also be checked this is how one can get the problem fixed.Solution for Updated Folder goes Missing From
    Gmail

    ReplyDelete

  15. The content has been written very well and also all the information has been framed in a very perfect manner. How can I resolve yahoo mail SMTP server error codes?

    ReplyDelete
  16. In order to get the AVG antivirus back to normal working, the user should get the system checked for conflicting programs closed lines are open all the time. Solution provided for fixing AVG not working

    ReplyDelete