General Advice Regarding Interoperability of Neverfail Engine with AntiVirus Solutions

General Advice Regarding Interoperability of Neverfail Engine with AntiVirus Solutions

Summary

This Knowledgebase article provides general information about interoperability with antivirus software.

More Information

Please consult and implement the Antivirus manufacturer’s advice, as Neverfail guidelines will often follow these recommendations.

General Principles

1. In order to avoid any problem with your Antivirus software, temporary files should not be replicated with Neverfail Engine.

2. The Antivirus software running on the Primary server must be the same as the Antivirus software which runs on the Secondary and Tertiary (if existing) server. In addition, the Antivirus must be running on both Active and Passive machines. Neverfail considers the Antivirus as a part of the operating system itself so it's ok for this to run on all servers in a Neverfail cluster. 

3. For getting virus definition updates on a Passive machine, Neverfail recommends using a management IP address. If a centralized AV server is used then the Neverfail Management Name feature can be configured to get the virus definitions on the Passive server too. For configuring Management Name, please see the following KB article https://support.neverfail.com/portal/en/kb/articles/how-to-enable-neverfail-engine-management-name-for-passive-node-management. Virus definitions can also be added manually on the Passive server.

4. After installation of Neverfail Continuity Engine, any changes made to the configuration of the Antivirus software on the Active server must be repeated manually on the Passive server.

5. The following services should be whitelisted (added to trusted list) in the Antivirus software:
            Neverfail Engine, Neverfail Webservices 

6. The following process should be whitelisted (added to trusted list of processes/applications) in the Anti-Virus software:
            NfServerR2.exe

7. The following Neverfail directory must be excluded from File Level Anti-Virus Scans:
            C:\Program Files\Neverfail\R2

8. Some Antivirus software block ports. In that case the following ports need to be opened/whitelisted"

9727 and 9728 - ports used by Neverfail Webservices service to communicate between Neverfail EMS web centralized console and the Primary, Secondary and Tertiary (if existing) servers.

57348 - port used for Neverfail Channel connection. This connection is used for data replication.

52267 - port used for Neverfail Advanced Management Client UI connection. 

9. File Level Antivirus should not be used to scan databases, for example Microsoft SQL Server databases or Microsoft Exchange databases. The nature of database contents can cause false positives in virus detection, leading to failure of database applications and data integrity errors. Performance will also be affected. 

Applies To

All Versions

Related Information

None

KBID-104


    • Related Articles

    • Neverfail Continuity Engine vs. antivirus solutions - installation considerations and recommendations

      Summary This Knowledgebase article offers information about the antivirus solutions having impact on Continuity Engine installation and which are the recommended mitigation actions. Symptoms Following symptoms may be observed during the Continuity ...
    • Continuity Engine Features and Benefits

      Neverfail offers a High Availability & Disaster Recovery solution focused on continuous availability. To ensure continuous availability, Neverfail uses fully redundant servers including a Primary server and the Secondary server. Each server is ...
    • Continuity Engine Troubleshooting - Synchronization Failures

      Neverfail Continuity Engine provides protection to your applications by replicating data to a passive server. Continuity Engine attempts to synchronize protected data on all servers and continually replicates changes to that data. This article ...
    • Continuity Engine Product Architecture

      Learning objectives At the completion of this session, you should be able to: Identify major components of the Neverfail Continuity Engine product architecture. Describe major component configuration. Identify advantages of the Neverfail Continuity ...
    • Neverfail IT Continuity Engine v7.1.2 - Release Notes

      Summary This Knowledgebase article provides information about this specific release of Neverfail IT Continuity Engine v7.1.2 Overview This release of Neverfail IT Continuity Engine is a patch release that applies to Neverfail IT Continuity Engine ...