30.01.2015 Views

Administrator's Guide - Kerio Software Archive

Administrator's Guide - Kerio Software Archive

Administrator's Guide - Kerio Software Archive

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Antivirus control<br />

Warning:<br />

1. Antivirus control within WinRoute can only detect and block infected attachments.<br />

Attached files cannot be healed by this control!<br />

2. Within antivirus scanning, it is possible to remove only infected attachments, entire<br />

email messages cannot be dropped. This is caused by the fact that the firewall cannot<br />

handle email messages like mailservers do. It only maintains network traffic coming<br />

through. In most cases, removal of an entire message would lead to a failure in<br />

communication with the server and the client might attempt to send/download the<br />

message once again. Thus, one infected message might block sending/reception of any<br />

other (legitimate) mail.<br />

3. In case of SMTP protocol, only incoming traffic is checked (i.e. traffic from the Internet<br />

to the local network — incoming email at the local SMTP server). Checks of outgoing<br />

SMTP traffic (i.e. from the local network to the Internet) might cause problems with<br />

temporarily undeliverable email (for example in cases where the destination SMTP<br />

server uses so called greylisting).<br />

To check also outgoing traffic (e.g. when local clients connect to an SMTP server without<br />

the local network), define a corresponding traffic rule using the SMTP protocol inspector.<br />

For details, see chapter 14.2.<br />

Advanced parameters and actions that will be taken when a virus is detected can be set in the<br />

Email scanning tab.<br />

In the Specify an action which will be taken with attachments... section, the following actions<br />

can be set for messages considered by the antivirus as infected:<br />

• Move message to quarantine — untrustworthy messages will be moved to a special<br />

directory on the <strong>Kerio</strong> Control host. The <strong>Kerio</strong> Control administrator can try to heal<br />

infected files and later send them to their original addressees.<br />

The quarantine subdirectory under the <strong>Kerio</strong> Control directory is used for the<br />

quarantine<br />

(the typical path is C:\Program Files\<strong>Kerio</strong>\WinRoute Firewall\quarantine)<br />

Messages with untrustworthy attachments are saved to this directory under names<br />

which are generated automatically by WinRoute. Each filename includes information<br />

about protocol, date, time and the connection number used for transmission of the<br />

message.<br />

• Prepend subject message with text — use this option to specify a text to be attached<br />

before the subject of each email message where at least one infected attachment is<br />

found. This text informs the recipient of the message and it can be also used for<br />

automatic message filtering.<br />

200

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!