| Monash home | About Monash | Faculties | Campuses | Contact Monash |
| Staff directory | A-Z index | Site map |
|
Sophos Installation via ZENworksThis document provides information on installing the Sophos Sweep anti-virus product on Monash University Windows workstations through the use of the Novell ZENworks product. Important Notes[1] This distribution is intended for use only on Monash University Windows computers in the staff or student Novell environment, as installed by the ZENworks installer. ITS will not support its use on other machines. Once installed, the software will receive updates both on and off campus. [2] In order for ZENworks to deploy applications to the workstation, the workstations must be running a supported Novell client and the ZENworks 6.5 agents, and be registered into the staff or student Novell tree. The version of the ZENworks agent can be checked by running NALWIN32.EXE and selecting About from the Help menu. The ZENworks 6.5 agent must be installed on workstations that have the older ZENworks 3.2 software by running NALWIN32.exe, then double-clicking on the ZENworks 6.5 Desktop Management Agents icon. Please see the ZENworks document for details on registering the workstations into the Novell tree. InstallationThe supplied ZENworks application object applies three TCP/IP port exceptions to the Windows firewall in order to allow bidirectional communication between the Sophos management system and the target server, then invokes the Sophos vendor's setup program to install the product. The installer will remove previous versions of Sophos anti-virus software, including the remote updater for version 4. Automatic installation to workstationsAll registered workstations in both Staff and Student environment will automatically install Sophos. Automatic Login script installation to staffDepartmental or Faculty IT managers can include the Sophos installer into their local Login_Profile by editing the login script and adding the following line: include .pro-Sophos.netadmin.resource.monash This will run the installer on login and install the software if the staff accounts are Administrator-equivalent on the local computer. Manual installation by staffIf visible to staff accounts, the ZENworks application object Sophos will be present in the SOE folder on both the Start menu and NAL application window. ConfigurationThe distribution archive comes preconfigured with a daily scan set to scan all files, and with the interactive scanning set to clean any infected files. Once installed, the product registers itself with the Sophos management system and allows centralised reporting and configuration. One important part of the configuration that is distributed to registered staff machines are the account and password details that allow roving staff machines (ie laptops) to continue to receive updates when not located on the Monash network. All Sophos managed workstations receive a policy from the Sophos management server. By default all workstations receive a standard Monash policy that has been configured by the ITS Security Group. Faculties can request their own policy to be created and have that policy applied to their workstations instead of the Monash policy. There are many configurable options within the sophos policy like, file and program authorisations, file exclusions and scanning schedules. By configuring a policy it will allow all your workstations to receive the settings you have requested without having to visit any machine as the policy is pushed out via the Sophos management server. To request a sophos policy to be applied to your workstations you will need to contact the ITS Service desk and log a call. All changes to Sophos policies need approval by the ITS Security Group. |