About Gateway Antivirus Settings; Pop3 Proxy Deny Messages And Gateway Av/Ips - Watchguard Firebox X15 User Manual

Firebox x edge e-series version 10 all firebox x edge e-series standard and wireless models
Hide thumbs Also See for Firebox X15:
Table of Contents

Advertisement

Gateway AntiVirus and Intrusion Prevention Service

About Gateway AntiVirus settings

WatchGuard Gateway AntiVirus (Gateway AV) stops viruses before they get to computers on your network.
Gateway AV operates with the WatchGuard SMTP, POP3, HTTP, and FTP proxies. When you enable Gateway
AV, the SMTP, POP3, HTTP, and FTP proxy looks at various types of traffic and performs an action that you
specify.
Gateway AntiVirus scans different types of traffic according to which proxy or proxies you use the feature with:
If you enable Gateway AntiVirus with the SMTP or POP3 proxy, it finds viruses encoded with frequently
used email attachment methods. These include base64, binary, 7-bit, 8-bit encoding, and uuencoding.
You can also use Gateway AV and the SMTP proxy to send virus-infected email to the Quarantine
Server.
If you enable Gateway AntiVirus with the HTTP proxy, it finds viruses in web pages that users try to
download.
If you enable Gateway AntiVirus with the FTP proxy, it finds viruses in uploaded or downloaded files.

POP3 proxy deny messages and Gateway AV/IPS

It is important to know what your users see when an email message is blocked because of the POP3 proxy. You
can find a complete description of the actions taken by the POP3 proxy in an FAQ you can find at
www.watchguard.com/support/faqs/edge/.
Some of the actions include:
o Send a message that an email message was denied when it blocks a message because of a
problem in the header, or because of the body or attachment content, and the message is less
than 100 kilobytes.
o Truncate an email message when it blocks a message because of a problem with the body or
attachment content, and the message is larger than 100 kilobytes.
o Block an email message with no notification to the user when an email message is blocked
because of a protocol anomaly.
You can see deny messages for all blocked email in the log messages. For information on using the log
message tool, see
Signatures for Gateway AV are not automatically updated by default. To make sure Gateway AV has
current signatures, see
248
To see the event log
file.
Update Gateway
AV/IPS.
http://
Firebox X Edge e-Series

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents