Handle Object Policy; Black-List And White-List - ESET NOD32 ANTIVIRUS - FOR LINUX-BSD MAIL SERVER Installation Manual

For linux/bsd mail server
Table of Contents

Advertisement

5.2. Handle Object Policy

The Handle Object Policy (see figure 5-1) is a mechanism that provides handling of the scanned objects depending
on their scanning status. The mechanism is based on so-called action configuration options ('action_on_processed' ,
'action_on_infected' , ‚action_on_uncleanable' , ‚action_on_notscanned') combined with Anti-Virus enabling
configuration option (‚av_enabled'). To get detailed information on these configuration options, please refer to the
nod32.cfg(5) manual page.
Figure 5-1. Scheme of Handle Object Policy mechanism.
av_enabled
NO
object accepted
Every object processed by NOD32LMS/NOD32BMS is at first handled with respect to the setting of the configuration
option 'action_on_processed' . Once this parameter is set to 'accept' , the object is handled according to the setting of
configuration option 'av_enabled' . Note that this parameter is of paramount importance if combined with so-called
User Specific Configuration mechanism. In this case various types of black-lists and white-lists can be configured.
Once 'av_enabled' is enabled the object processed is scanned for virus infiltrations and set of action configuration
options 'action_on_infected' , 'action_on_uncleanable' and 'action_on_notscanned' is taken into account to evaluate
further handling of the object. If action 'accept' has been taken as a result of the three above action options or 'av_
enabled' is disabled the object is accepted for further delivery. In case any of action configuration options caused other
than ‚accept' value, the object is blocked and will be handled according to the particular action taken.

5.3. Black-list and white-list

In this section we describe the black-list and/or white-list creation using the combination of already discussed
NOD32LS/NOD32BS configuration mechanisms. In particular the black-list or white-list can be created using the Handle
Object Policy features and User Specific Configuration mechanism. Thus the black-list or white-list can be created for
recipients and/or senders of e-mail messages scanned by NOD32LS/NOD32BS.
In the next example we demonstrate the black-list and also white-list creation for the nod32smtp module as a
content filter of MTA Postfix. The original configuration section related to the module is as follows,
agent_enabled = yes
listen_addr = "localhost"
listen_port = 2526
chapter 5 / Important NOD32LMS/NOD32BMS Mechanisms
action_on_processed
accept
action_on_infected
YES
action_on_uncleanable
action_on_notscanned
accept
defer, discard, reject
defer, discard, reject
object not accepted
object not accepted
33

Advertisement

Table of Contents
loading
Need help?

Need help?

Do you have a question about the NOD32 ANTIVIRUS - FOR LINUX-BSD MAIL SERVER and is the answer not in the manual?

This manual is also suitable for:

Nod32 antivirus system

Table of Contents