Re: Run a Virus Scan on DCs?

Tech-Archive recommends: Fix windows errors by optimizing your registry



Howdie Flash!

Flash3200 wrote:
Should I run a dedicated Virus Scan on my Domain Controllers? We have
McAfee Enterprise ViruScan loaded on them and they are enabled to pick
up something as it runs live on the server, but I run a dedicated scan
once a week on all my other servers and I've heard both ways when it
comes to DCs... "no you shouldn't run a scan cause it slows them down
too much (regardless of memory???)" and also "Sure why not.. whats it
going to hurt". So I'd like to get everyone else's opinions!!!!

I'll tell you my opinion on this - maybe you're interested in that as well ;-)

I'm no big fan of antivir applications Domain Controllers. The reason is: why should I scan? See, the Domain Controller is THE part of your domain. I really mean THE part. What will happen if those controllers break? Your business is pretty much like to go down - all the way with your productivity and the big bucks. Not more, not less. I have the philosophy that I lock them down as much as possible - physically as well as technically.

I also think that there shouldn't run any services other than Active Directory and the DNS service. The question then is: how can you nest there any virses or malware, if there are no users logging in to that machine (other than you and your admin-buddies), no services/shares with write-access for people.

From the "what's it going to hurt"-perspective, I've seen environments where the antivoir did block access to the SYSVOL share and broke Group Policy application down. People needed to exclude the SYSVOL folder from scanning in order to have those services run again. This can actually be a time-consuming search if you're not immediately thinking of your antivir while troubleshooting.

If you really consider using an antivir on your domain controllers, be careful when installing and ask the vendor if there are any issues with Active Directory. A loss of a domain controller (a loss may also mean a downtime of a few minutes/hours) can cause your whole network to be unstable (it shouldn't if you have multiple domain controllers - but how frequent do you try that out?).

- Be careful, that's what I'm sayin' ;-)

cheers,

Florian
--
eMail: prename [at] frickelsoft [dot] net.
blog: http://www.frickelsoft.net/blog.
.



Relevant Pages

  • Re: What are the best general things to do after a dirty shutdown (Server SBS)
    ... You should check the dirctory services event log and the system event logs for errors and warning in addition to running the dcdiag /c /v command. ... This event can occur if the domain controllers ... Directory Server Diagnosis ... Verifying that the local machine ALPHA, ...
    (microsoft.public.windows.server.sbs)
  • Re: What are the best general things to do after a dirty shutdown (Server SBS)
    ... You should check the dirctory services event log and the system event logs for errors and warning in addition to running the dcdiag /c /v command. ... This event can occur if the domain controllers ... Directory Server Diagnosis ... Verifying that the local machine ALPHA, ...
    (microsoft.public.windows.server.sbs)
  • Re: What are the best general things to do after a dirty shutdown (Server SBS)
    ... test network connectivity to local domain controllers. ... Directory Server Diagnosis ... Verifying that the local machine ALPHA, ... The File Replication Service Event log test ...
    (microsoft.public.windows.server.sbs)
  • Re: GP to force Daily Restart
    ... The Security System could not establish a secured connection with the server ldap/DC01.corp.com/corp.com@xxxxxxxxx No authentication protocol was available. ... The network path was not found. ... domain controllers log these events every five minutes. ... every computer on the network must use DNS servers that can resolve SRV ...
    (microsoft.public.windows.server.sbs)
  • Re: Net logon error event id:3096
    ... Verifying that the local machine yblrtgswip1, ... Connecting to directory service on server yblrtgswip1. ... No record of File Replication System, ... interval between domain controllers. ...
    (microsoft.public.win2000.active_directory)