Anti-Virus Scanning; Overview - D-Link NetDefendOS User Manual

Network security firewall
Hide thumbs Also See for NetDefendOS:
Table of Contents

Advertisement

6.5. Anti-Virus Scanning

6.5.1. Overview

The NetDefendOS anti-virus module protects against malicious code carried in files being
downloaded to clients via a NetDefend Firewall. The following can be scanned for viruses:
Files downloaded via the firewall. For example, files downloaded using HTTP transfer or FTP
or perhaps or as an attachment to an email.
Scripts contained within webpages delivered via HTTP.
URLs contained within webpages delivered via HTTP.
Malicious code in downloads can have different intents ranging from programs that merely
cause annoyance to more sinister aims such as sending back passwords, credit card numbers and
other sensitive information. The term "Virus" can be used as a generic description for all forms of
malicious code carried in files.
Combining with Client Anti-Virus Scanning
Unlike IDP, which is primarily directed at attacks against servers, anti-virus scanning is focused on
downloads by clients. NetDefendOS anti-virus is designed to be a complement to the standard
anti-virus scanning normally carried out locally by specialized software installed on client
computers. It is not intended as a complete substitute for local scanning but rather as an extra
shield to boost client protection. Most importantly, it can act as a backup for when local client
anti-virus scanning is not available.
Enabling Using IP Rules or IP Policies
Anti-virus scanning can be enabled using either an IP Rule object or an IP Policy object and this
section includes examples for using both methods.
Anti-Virus with IP Rules
With an IP Rule object, anti-virus scanning is first enabled on the relevant ALG for the targeted
traffic. Then, that ALG is associated with a Service object which is in turn is associated with an IP
rule. Anti-virus scanning can be enabled for file downloads associated with the following ALGs:
HTTP ALG
FTP ALG
POP3 ALG
SMTP ALG
Note that there is no IMAP ALG but scanning of email attachments in IMAP traffic can be
achieved by enabling anti-virus scanning on IP policies that trigger on that traffic.
Anti-Virus with IP Policies
As shown later in this section, configuring anti-virus scanning using an IP Policy object is simpler
than with an IP Rule object since it is not necessary to configure separate ALG and service objects.
However, certain ALG options are not available when using IP policies. Such an unavailable
541
Chapter 6: Security Mechanisms

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents