Answer
PROBLEM
Scans from the console are slow or taking a long time.
As GFI LanGuard continually increases the number of supported applications to be scanned and the number of patches available for supported applications grows, it inevitably takes longer times to scan, particularly during scans from the console (interactive and console scheduled scans). In order to scan a computer remotely, the GFI LanGuard server must connect to the target machine and communicate back and forth for information through SMB/RPC protocols on registry keys, file information, WMI data, and other information. Therefore, the following factors can significantly affect scanning speed:
As GFI LanGuard continually increases the number of supported applications to be scanned and the number of patches available for supported applications grows, it inevitably takes longer times to scan, particularly during scans from the console (interactive and console scheduled scans). In order to scan a computer remotely, the GFI LanGuard server must connect to the target machine and communicate back and forth for information through SMB/RPC protocols on registry keys, file information, WMI data, and other information. Therefore, the following factors can significantly affect scanning speed:
- Network Location of the target computers and latency
- Selection of scanning profile (the items GFI LanGuard will include in it's scan)
- The current load on the target computer by its installed programs
ENVIRONMENT
- GFI LanGuard (all versions)
- All supported environments
SOLUTION
Modify your scanning using one or more of the following suggestions:- Verify machines meet minimum System Requirements
- Schedule your scans during periods when network usage is lowest
- Schedule your scans during periods the target computers will not be in use.
- Customize scanning profiles to disable all checks which are not applicable for your environment or are not of interest such as the following:
- Port Scanning - this is especially time consuming.
- Vulnerability scanning (if your main emphasis is on patching).
- Application scanning (especially the option to enable Full Security Applications Audit for Agentless Scans - LanGuard must do a deployment of approximately 50 files to the target computer to collect this information)
- Split scanning into different scheduled scans at different times using different profiles (ex. Alternate daily scans for missing patches and vulnerability scans, scan once weekly for installed applications and once weekly for port scanning).
- Increase the number of scan threads (in the profiles scanner options) to 8. This will allow 8 computers to be scanned at a single time (we do not recommend going higher than this number).
- Install agents and relay agents on as many computers as your policies will allow.
CAUSE
GFI LanGuard must connect to and query each computer and query for information about each and every item it is configured to check. This results in a high volume of back and forth network communications.Related Articles:
Priyanka Bhotika
Comments