Virus Blockers Common

From Edge Threat Management Wiki - Arista
Revision as of 17:36, 4 April 2016 by Dmorris (talk | contribs)
(diff) ← Older revision | Latest revision (diff) | Newer revision → (diff)
Jump to navigationJump to search

Settings

This section reviews the different settings and configuration options available for the virus scanners.


Web

This section reviews the different settings and configuration options for web traffic.

  • Scan HTTP: This enables or disables HTTP scanning.
  • File Types: The File Types section allows you to scan files by file extension - just select (or add) your chosen file extension, check your preferred action (scan or not), and save.
  • MIME Types: The MIME Types section allows you to scan files by MIME types - just select (or add) your chosen file extension, check your preferred action (scan or not), and save.


Email

This section reviews the different settings and configuration options for email traffic.

  • Scan SMTP: This option enables scanning of SMTP message attachments.
  • Action: The selected action will be taken on a message if a virus is found.
Setting Action to Remove Infection will remove the infected attachment and wrap the original email for delivery to the intended recipient. If set to Pass Message, the original message will be wrapped and delivered with the attachment intact. In both cases, the subject line is prepended with "[VIRUS]". Block will block the message from being delivered.


FTP

This section reviews the different settings and configuration options for FTP traffic.

  • Scan FTP: This enables or disables scanning of FTP downloads.


Pass Sites

This section allows you to specify sites that are not scanned. The list uses the Glob Matcher syntax.

NOTE: Use caution when adding sites to this list!

For each protocol, the behavior is as follows:

  • HTTP. Match the HTTP Host header.
  • FTP. Match the server IP address or domain address (if a reverse DNS address exists).
  • Email. Match the client or server IP address or domain address (if a reverse DNS address exists).