When pop is used, the URL is "pop://POP user name@POP server name:port number".
When smtp is used, the URL is "mail:destination".
• User name
Displays the user name when proxy authentication is used.
"-" is recorded if authentication is not used.
• Hierarchy code
Returns "[Hierarchy string]/IP address of destination".
[Hierarchy string] is not used. "DIRECT" is always used.
• Content-Type
Displays the Content-Type of the file to be transferred. "-" is used when not available.
• Detection information
"DETECT-STAT:[Detection results]:[Virus name]:[File name]:[Quarantined file name]::" is
returned.
Detection results
Virus name
File name
Quarantined file
name
• Action
"ACTION:[Action]:" is returned.
Action
• Proxy information
"PROXY-STAT:[Service type]:[Internal process ID]:[Process ID] :[IP address of
host]:[Number of processed files]:[Number of checks]:[Detection time]:[Detection details]:"
is returned.
Service type
Internal process ID
Process ID
IP Address of host
Number of
processed files
Number of checks
F-Secure Internet Gatekeeper for Linux/Administrator's Guide
Either INFECTED (Virus detected), SPAM (Spam detected), or CLEAN (No virus
detected)
Name of the virus
Name of the file being transferred
The name of the file as it is stored in the quarantine directory
This is set only if the quarantine of infected files is enabled.
Either of the following actions are returned according to the detection results:
NONE
・
・
PASS
DELETE
・
・
DENY
・
SENDBACK
・
BLACKHOLE
・
CHANGE_SUBJECT Spam detected with SMTP and the subject is
・
・
Indicates the service type (http, smtp, pop, ftp)
Indicates the internal process ID (identifier starts with 0) used for the process.
In general, smaller numbers have higher priority.
[internal process ID]+1) applies to the simultaneous number of connections during
startup of the corresponding access.
Indicates the process ID that is used for the process
Indicates the IP Address of the host
Indicates the number of requests processed in the same session. Starts with 1 and
increments by 1 for each access log generated in the same session. For POP, 1 is
always used.
The number of virus checks executed in one connection
(the number applies to the number of times since the last time an access log was
Nothing is done (No detection)
Detected but passed (logged)
Deleted (If SMTP is used, a notification is sent to
the recipient after the file is deleted)
Detected with SMTP and blocked
Notification sent to the sender with SMTP
Deleted with SMTP (no notification to the sender)
changed
76
Need help?
Do you have a question about the INTERNET GATEKEEPER FOR LINUX 4.01 and is the answer not in the manual?
Questions and answers