General V7 Observations and Requests

Hi
I’d like to comment on a few detractions of version 7.

Firstly version 7 arrived out the blue on my work PC just because I was working on the Internet - it upgraded itself from version 6 with no prior authorization from the central server. It would be good to prevent this behaviour before releasing version 8.

Secondly there is no way we can get working to roll out version 7 clients or definitions using alternative mechanisms. This is particularly frustrating as we only just fixed version 7 after it stopped working for 9 days! (Mirror bug caused this). Free version users can at least download the latest VPS defs and manually update but it is incompatible with the Endpoint business version. We need to package and deploy via MS SCCM. We can dynamically package new versions but right now the package builds are all broken except if the server does the deployment itself. If there are any issues requiring a manual install can’t do it.

Thirdly Secondary mirror seems like a good idea on our large network with slow links but it seems largely undocumented how to get it to work and point clients to it. Be nice to have a deployment guide.

Fourthly the reports are great but deployment coverage reports give wildly erroneous information

Fifthly it would be great to have Organizational unit discovery inclusions/exclusions on AD discovery and also exclude disabled objects - I keep getting computers that are disabled / decommed or I don’t want to install Avast on (some vendors specify they will not support all AVs so we also run McAfee for a limited number of systems, others don’t want AV at all e.g. TMG firewall - but you can delete them they will just come back)

Six - Auxiliary tasks seem great - but can we please have an aux task to do a computer reboot - that way we can schedule a reboot of computers in a collection showing reboot required at a convenient maintenance window.

Seven - Nowhere on the admin console can you see what the latest VPS is in the mirror - there is no monitor if the mirror is out of date - e.g. 3 days old and also you are just assuming that there is an update daily when you look at reports and working out what is out of date. Same goes for program version - how do I know I got the latest program - especially seeing as my home computer updated a few days ago I think there may be a new version but I am just assuming it is not released yet on business version - it would be good to know.

Eight - back to discovery - why can’t discovery determine from computer properties which group to put an object into? All workstations and servers just go into root node and have to get sorted out.

Nine - license lock and update - we bought a new license and it would not load - needed to get the update from tech support - thanks guys! However it seems that license updates does not work too well. Needs a rethink - bottom line is if we buy a company we need to buy a supplementary license for the new workstations and servers and load it without issues. Related to which, because discovery rediscovers old non-existant stuff out of AD and there is a random computer lockout facility its just a lucky dip which computers get locked out and which ones don’t. It would be great to have a mechanism (maybe a special non-client group?) to put in the computers you really want to lock out so the license can be released for valid use. You can even go ahead and test those objects for Avast program presence so license violation is not possible.

Ten - installation packages - would be nice to have an option to do a program only package so that installation can be phased to utilize bandwidth better. Typically we only uninstall the legacy AV once its all confirmed working so going “unprotected” for a day or two is less of an issue than the impact of parralel deployment down small lines. (Yes we do tweak down the parallelism of the deployment task which is nice, but the size of the package also slows down the deployment.

Eleven - Reporting - how nice it would be to be able to do some LDAP discovery of computer object properties like the OU, the item manager and possibly user specified properties in order to create our own dynamic groups and produce reports restricted to groups - this would give us all the flexibility to report to different departments on their sysems, rather than having to put in a lot of manual effort.

Our impression is that the new version seems to be based on an older version console, so some of the strengths of the old version are back but version 6 did have some better things too and this was also just thrown out. On the whole version 7 is an improvement, but I know I have around 9 months before I have to show my CIO we now have something significatly closer to what I described above or we will move to another product. I am personally a great believer in Avast but do have the frustration that the personal product seems to be significantly better and more under control than the corporate offering.

Well written!

I agree with your summary statement. I’ve been on Avast 4.8 Pro for many years now at my company. I recently extended it through the end of this year because I don’t feel the business product is ready yet. But time is ticking and I have 6 months to either roll out Avast’s new offering or find another AV solution.

I am a big fan of how 4.8 Pro was released. It allowed me to roll out the software purely through login script and with silent installs w/configs pre-set for the client machines. I don’t have a console, or central administration - but I do have audit software that will tell me if a PC is throwing up a Security Center alert (such as Avast out of date).

I keep lurking here, watching the threads, and am nervous about testing the Avast 7 just yet. I think I’ll wait a few more months and see if things get hashed out before spending time in a lab.

Hey ! I agree with you !!
I’m in the same case as Dewg

V7 looks like v4.8 but missing lot of good things (aswchams.exe, …), or not working old fonctions that was working before (ip descovering)

I hope we’ve got a big patch before the end of the year, actualy V7 looks like a beta version …

Documentations a realy missing

  • AEA Console
  • Mirroring

I’ve been waiting since the second for a response from support on licensing issues.
If I don’t hear back soon, we’ll have no choice but to get a refund on our 21 licenses and look at a a different solution

The thing that bothers me, isn’t the buggy v7, it’s the apparent lack of support

Hi

I want to give an update as most of my issues are now addressed. Firstly it is important to get up to version 7.7.1455 to get most things sorted.
Reading the manual sorts out a lot :slight_smile:
Issues I have remaining is that there is still manual work getting grupings right and a new nasty discovery :-

You must match your deployment package to your policy groups at the shields level. You cannot set policies for shields not deployed and also you can deploy wrong shields.
You can always tweak the settings for a shield but it is a nasty uninstall, reboot, install, reboot cycle to ensure the incorect shields don’t run. Oh and even that won’t work without manually intervening to switch off program protection feature and run the avast uninstall tool.

So e.g. if your Exchange server cannot communicate to the Avast server and you installed the anti-spam shield in your package it can change from waiting to start to running and start doing anti-spam stuff you don’t necessarily want! Also if you forgot to package the IMShield and now need it on a workstation, you cannot just enable it by policy, because it is not installed!

Als don’t schedule package genration - do it manually and check the size is around 145MB - then you can use than in SCCM or some other deployment tool - but gen a package for every policy group and ensure you target the right machines to avoid the issues described above.

nice points Trevor!

maybe you can post some of it a little bit rewritten in the thread i created ?
http://forum.avast.com/index.php?topic=101270.0

Thank you for your feedback Trevor, I will discuss it with our DEV team together with the listed points in here: http://forum.avast.com/index.php?topic=101270.0

Mirror update bug was fixed together with other issues mentioned here: http://forum.avast.com/index.php?topic=101245.0 + some other minor issues…

Thank you for answering Markvi, maybe you could also keep us up to date about the points mentioned ? thank you