Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
jteep
New Contributor

Azure Backup with antivirus - cbengine.exe

Hi,

 

We are running a Windows 2012 VM in Azure. It has Azure File Backup enabled, creating 3 daily backups, and Azure Snapshots enabled, creating nightly snapshots.

 

The snapshots are done at the VHD level, and therefore forticlient does not see it, and it has no system impact.

 

The file/folder backups however are done using Azure's 'Backup' module/software. The backup process is called 'cbengine.exe'

 

This cbengine.exe effectively reads every single file in the VM, and sends incremental backups to Azure. Because this is at the software level rather than the VHD level, Forticlient Antivirus sees this as a 'file read', and is scanning every single file 3 times a day.

This not only slows down the backup process so that many of them 'overlap' (i.e. the next backup schedule tries to start before the last one finishes), but it also means the processor is consistently running at 90% whilst it scans everything.

 

Is there any way to exclude Forticlient Antivirus from processing files that are read from cbengine.exe?

 

Thanks

4 REPLIES 4
MikePruett
Valued Contributor

Have you tried making FortiClient ignore the .exe in question? (I assume it is a file that is local to the machine, perhaps an agent, that is doing this?)

Mike Pruett Fortinet GURU | Fortinet Training Videos
jteep

We have added the full file location of 'cbengine.exe' to the file exclusion list, but this has not made a difference - I presume this is excluding cbengine.exe from itself being scanned, rather than stopping the files it is accessing/transferring from being scanned.

jteep
New Contributor

Can anyone else help on this? Is there any way of excluding a 'process' as well as files/folders?

Chris_Lin_FTNT

I was wondering how many files/folders you were trying to backup, with cbengine.exe?

 

Can you try this:

1. disable real-time protection in FortiClient GUI.

2. open an administrative cmd.exe, configure as much rollback buffer as possible, go to FortiClient directory, before your scheduled backup starts, run "fmon.exe -s AS_01".

3. It will show what files are scanned. Hopefully it will give a hint.

Labels
Top Kudoed Authors