Administrator's Guide - Kerio Software Archive

Administrator's Guide - Kerio Software Archive Administrator's Guide - Kerio Software Archive

download.kerio.com
from download.kerio.com More from this publisher
30.01.2015 Views

Antivirus control Warning: 1. The purpose of the antivirus check is only to detect infected files, it is not possible to heal them! 2. If the antivirus check is disabled in HTTP and FTP filtering rules, objects and files matching corresponding rules are not checked. For details, refer to chapters 13.2 and 13.5). 3. Full functionality of HTTP scanning is not guaranteed if any non-standard extensions to web browsers (e.g. download managers, accelerators, etc.) are used! To set parameters of HTTP and FTP antivirus check, open the HTTP, FTP scanning tab in Configuration → Content Filtering → Antivirus. Figure 14.7 Settings for HTTP and FTP scanning 196

14.3 HTTP and FTP scanning Use the If a virus is found... entry to specify actions to be taken whenever a virus is detected in a transmitted file: • Move the file to quarantine — the file will be saved in a special directory on the Kerio Control host. Kerio Control administrators can later try to heal the file using an antivirus program and if the file is recovered successfully, the administrator can provide it to the user who attempted to download it. The quarantine subdirectory under the Kerio Control directory is used for the quarantine (the typical path is C:\Program Files\Kerio\WinRoute Firewall\quarantine) Infected files (files which are suspected of being infected) are saved into this directory with names which are generated automatically. Name of each file includes information about protocol, date, time and connection number used for the transmission. Warning: When handling files in the quarantine directory, please consider carefully each action you take, otherwise a virus might be activated and the Kerio Control host could be attacked by the virus! • Alert the client — Kerio Control alerts the user who attempted to download the file by an email message warning that a virus was detected and download was stopped for security reasons. Kerio Control sends alert messages under the following circumstances: The user is authenticated and connected to the firewall, a valid email address is set in a corresponding user account (see chapter 16.1) and the SMTP server used for mail sending is configured correctly (refer to chapter 18.3). Note: Regardless of the fact whether the Alert the client option is used, alerts can be sent to specified addresses (e.g. addresses of network administrators) whenever a virus is detected. For details, refer to chapter 19.4. In the If the transferred file cannot be scanned section, actions to be taken when the antivirus check cannot be applied to a file (e.g. the file is compressed and password-protected, damaged, etc.): • Deny transmission of the file — Kerio Control will consider these files as infected and deny their transmission. Hint: It is recommended to combine this option with the Move the file to quarantine function — the firewall administrator can extract the file and perform manual antivirus check in response to user requests. 197

14.3 HTTP and FTP scanning<br />

Use the If a virus is found... entry to specify actions to be taken whenever a virus is detected<br />

in a transmitted file:<br />

• Move the file to quarantine — the file will be saved in a special directory on the<br />

<strong>Kerio</strong> Control host. <strong>Kerio</strong> Control administrators can later try to heal the file using<br />

an antivirus program and if the file is recovered successfully, the administrator can<br />

provide it to the user who attempted to download it.<br />

The quarantine subdirectory under the <strong>Kerio</strong> Control directory is used for the<br />

quarantine<br />

(the typical path is C:\Program Files\<strong>Kerio</strong>\WinRoute Firewall\quarantine)<br />

Infected files (files which are suspected of being infected) are saved into this directory<br />

with names which are generated automatically. Name of each file includes information<br />

about protocol, date, time and connection number used for the transmission.<br />

Warning:<br />

When handling files in the quarantine directory, please consider<br />

carefully each action you take, otherwise a virus might be activated and<br />

the <strong>Kerio</strong> Control host could be attacked by the virus!<br />

• Alert the client — <strong>Kerio</strong> Control alerts the user who attempted to download the file by<br />

an email message warning that a virus was detected and download was stopped for<br />

security reasons.<br />

<strong>Kerio</strong> Control sends alert messages under the following circumstances: The user<br />

is authenticated and connected to the firewall, a valid email address is set in<br />

a corresponding user account (see chapter 16.1) and the SMTP server used for mail<br />

sending is configured correctly (refer to chapter 18.3).<br />

Note: Regardless of the fact whether the Alert the client option is used, alerts can<br />

be sent to specified addresses (e.g. addresses of network administrators) whenever<br />

a virus is detected. For details, refer to chapter 19.4.<br />

In the If the transferred file cannot be scanned section, actions to be taken when the antivirus<br />

check cannot be applied to a file (e.g. the file is compressed and password-protected, damaged,<br />

etc.):<br />

• Deny transmission of the file — <strong>Kerio</strong> Control will consider these files as infected and<br />

deny their transmission.<br />

Hint:<br />

It is recommended to combine this option with the Move the file to quarantine<br />

function — the firewall administrator can extract the file and<br />

perform manual antivirus check in response to user requests.<br />

197

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!