Summary of Contents for KAPERSKY ANTI-VIRUS 5.6 - FOR MICROSOFT ISA SERVER 2004-2006 STANDARD EDITION
Page 1
KASPERSKY LAB Kaspersky Anti-Virus 5.6 for Microsoft ISA Server 2004/2006 Standard Edition ADMINISTRATOR'S GUIDE...
Page 2
K A S P E R S K Y A N T I - V I R U S 5 . 6 F O R M I C R O S O F T I S A S E R V E R 2 0 0 4 / 2 0 0 6 S T A N D A R D E D I T I O N Administrator's Guide Kaspersky Lab http://www.kaspersky.com...
Contents CHAPTER 1. KASPERSKY ANTI-VIRUS® FOR MICROSOFT ISA SERVER ..5 1.1. Hardware and software requirements ............... 6 1.2. Distribution kit ....................7 1.2.1. License Agreement ..................7 1.3. Services provided for registered users .............. 8 CHAPTER 2. TYPICAL DEPLOYMENT SCENARIOS ..........9 CHAPTER 3.
Page 4
Kaspersky Anti-Virus 5.6 for Microsoft ISA Server 2004/2006 Standard Edition 4.8.1. Installing a new license key ..............57 4.8.2. Renewing your license ................59 4.8.3. Removing a license key ................60 CHAPTER 5. FREQUENTLY ASKED QUESTIONS ..........61 APPENDIX A. GLOSSARY ..................65 APPENDIX B.
CHAPTER 1. KASPERSKY ANTI- VIRUS® FOR MICROSOFT ISA SERVER ® Kaspersky Anti-Virus for Microsoft ISA Server (hereafter, also Kaspersky ® Anti-Virus for ISA Server) is a system of anti-virus protection of files trans- ferred using the HTTP and FTP protocols via the Microsoft Internet Security and Acceleration Server.
Kaspersky Anti-Virus 5.6 for Microsoft ISA Server 2004/2006 Standard Edition ® In addition, Kaspersky Anti-Virus for Microsoft ISA Server allows the administra- tor to: Set parameters for anti-virus protection and for notifications about dan- gerous events. Create groups of clients in accordance with the adopted network policy. For example, you can use the existing administration division to define anti-virus policy settings for each of the groups created.
Kaspersky Anti-Virus® for Microsoft ISA Server At least 200 Mb hard disk space for temporary storage of data copied from the Internet before scanning for viruses. Note: The amount of free disk space required to temporarily store data downloaded from the Internet before an anti-virus scan starts depends on the density of traffic processed by Microsoft ISA Server.
Kaspersky Anti-Virus 5.6 for Microsoft ISA Server 2004/2006 Standard Edition If you do not agree to the terms of this LA, you can return the unused product to ® your Kaspersky Anti-Virus dealer for a full refund, making sure the envelope containing the CD is sealed.
CHAPTER 2. TYPICAL DEPLOYMENT SCENARIOS A typical scenario for deploying ISA Server and most of its server applications and filters is as follows: the administrator installs the application on the ISA Serv- er computer, and the ISA administration tool on a remote computer (as a rule, an administrator’s workstation).
Page 10
Typical deployment scenarios Figure 1. Processing of data streams by Kaspersky Anti-Virus for Microsoft ISA Server...
CHAPTER 3. INSTALLING THE APPLICATION ® To correctly install the Kaspersky Anti-Virus application, you should first proper- ly configure FTP Access Filer, a standard filter for ISA Server. If you also use Microsoft Internet Security and Acceleration Server 2004 Service Pack 2, you need to configure support for decompression of HTTP objects.
Kaspersky Anti-Virus 5.6 for Microsoft ISA Server 2004/2006 Standard Edition traffic before it is transferred to Web filters for processing (compressed content support). To enable content compression support: In the console tree of the ISA Management main window, select the Microsoft Security Acceleration...
Installing the application stallation or custom installation and restore an Anti-Virus configuration in the case of an incorrect installation. Warning! To install Kaspersky Anti-Virus for Microsoft ISA Server 2004/2006 Standard Edition, the user must have server administrator rights. During installation of Kaspersky Anti-Virus, several errors might occur. Each of these errors causes termination of Kaspersky Anti-Virus installation.
Page 14
Kaspersky Anti-Virus 5.6 for Microsoft ISA Server 2004/2006 Standard Edition Warning! ® If you want to install Kaspersky Anti-Virus for ISA Server administration console on a computer, make sure that Microsoft Windows 2000 (with Service Pack 4 and higher) and ISA Server administration tools are installed on this computer! Figure 2.
Page 15
Installing the application Figure 3. Selecting the administration console to install Step 4. Anti-virus protection settings In this installation step, you must define the anti-virus protection settings that will be used as default values (Fig. 4). The following settings can be adjusted: File system folder for storing the scan queue.
Page 16
Kaspersky Anti-Virus 5.6 for Microsoft ISA Server 2004/2006 Standard Edition Each of the above parameters has a default value. To change the default values, click the corresponding buttons or enter data into the corresponding fields. Figure 4. Default settings for the application Immediately after this stage is completed, the program will start copying files to your computer.
Page 17
Installing the application Step 5. Completing the setup In this step, the wizard informs you that Kaspersky Anti-Virus has been success- fully installed. Figure 5. Complete the setup You can also run a wizard for automatic installation of application license keys by selecting the corresponding box (see Figure 5).
Kaspersky Anti-Virus 5.6 for Microsoft ISA Server 2004/2006 Standard Edition Figure 6. Selecting the license key It is possible to install license keys after the application is installed (see sec- tion 4.8 on page 56). Warning! Without an installed license key, Kaspersky Anti-Virus will not scan traffic and the anti-virus database will not be updated.
Installing the application 3.3. Upgrading If your server has Kaspersky Anti-Virus 5.5 for Microsoft ISA Server 2004 in- stalled, you can upgrade it to Kaspersky Anti-Virus 5.6 for Microsoft ISA Server 2004/2006. To upgrade the application, launch the installer (see section 3.2.1 on page 13 for details).
CHAPTER 4. USING KASPERSKY ANTI-VIRUS ® After the application is installed and the Microsoft ISA Server services are res- tarted, Kaspersky Anti-Virus is ready to start scanning data streams because all the parameters necessary for the scan have been already set by default. Kas- persky Anti-Virus can be managed: Locally, if the server part (anti-virus kernel, anti-virus database and filters for Microsoft ISA Server) and administration tools (Administration Con-...
Page 21
® Using Kaspersky Anti-Virus Data not sent to the client before scan completes, % – 10 %. Enable partial content download – enabled. Error messages sent to the client. <html> <head> <title>Kaspersky Anti-Virus for Microsoft ISA Server</title> </head> <body> <h1>Kaspersky Anti-Virus for Microsoft ISA Server</h1>...
Kaspersky Anti-Virus 5.6 for Microsoft ISA Server 2004/2006 Standard Edition ber of days is set in the Notify about license expiration field and it is seven days by default. The administrator is notified by messages displayed in ® the system log on the computer running Kaspersky Anti-Virus for ISA Server.
Page 23
® Using Kaspersky Anti-Virus the corresponding item from the shortcut menu. To open the shortcut menu, right-click the corresponding node in the Kaspersky Anti-Virus application node (Fig. 8). To configure management settings, use the following capabilities of Kaspersky ® Anti-Virus for ISA Server.
Kaspersky Anti-Virus 5.6 for Microsoft ISA Server 2004/2006 Standard Edition Figure 8. Shortcut menu 4.2.1. Configuring general settings of anti- virus scans The administrator may need to change general settings of anti-virus protection. To edit general settings of anti-virus scanning: ®...
Page 25
® Using Kaspersky Anti-Virus Figure 9. The General tab The Anti-Virus tab (see Figure 10) displays general settings of Kaspersky Anti- ® Virus...
Page 26
Kaspersky Anti-Virus 5.6 for Microsoft ISA Server 2004/2006 Standard Edition Figure 10. The Anti-Virus tab In the upper part of the tab, you can see the following scan settings (Fig. 10): If you want to enable extracting and scanning of archives, check the Scan archives box.
Page 27
® Using Kaspersky Anti-Virus Note: If the extracting archives control is disabled, the archives will be scanned as ge- neric files. In this case, the program will detect only those viruses that have pe- netrated the archive file. Note: When scanning multi-volume archives, Kaspersky Anti-Virus scans each of the volumes as a separate object.
Page 28
Kaspersky Anti-Virus 5.6 for Microsoft ISA Server 2004/2006 Standard Edition applications (SpyWare) and applications used to broadcast unsolicited advertisements (AdWare). Spy application allow unauthorized users to get access to personal informa- tion, such as web browser history, passwords, bank accounts, etc., and send it to interested parties.
Page 29
® Using Kaspersky Anti-Virus Figure 11. The Settings tab Warning! ® Kaspersky Anti-Virus for Microsoft ISA Server can run simultaneously with other anti-virus programs in order to protect the file system of your computer (for ex- ® ample, Kaspersky Anti-Virus for Windows File Servers).
Page 30
Kaspersky Anti-Virus 5.6 for Microsoft ISA Server 2004/2006 Standard Edition To enhance the efficiency in processing large amounts of data, Kaspersky Anti-Virus® can simultaneously run several anti-virus kernels. By default, four anti-virus kernels are formed and run simultaneously during application startup.
® Using Kaspersky Anti-Virus Note: You can set a value ranging from 1 to 86400 seconds, inclusive. The default val- ue is 1800. Warning! If an object is not scanned during the specified time, it will be flagged as clean and sent to the client.
Page 32
Kaspersky Anti-Virus 5.6 for Microsoft ISA Server 2004/2006 Standard Edition If an infected file was detected after the first chunk of data con- taining a part of this infected file had been sent to the client, the program terminates the connection. Upon the second request for this file, the client will be immediately notified that the re- quested file is infected.
® Using Kaspersky Anti-Virus ® Set the percentage of data accumulated by Kaspersky Anti-Virus subsequent analysis and scanning in the Data not sent to the client be- fore scan completes, % field. The Enable partial content download checkbox enables/disables partial down- loading of data in cases, for example, of an Internet connection failure when downloading a file.
Kaspersky Anti-Virus 5.6 for Microsoft ISA Server 2004/2006 Standard Edition Figure 13. The FTP tab 4.2.2. Managing client groups Each group includes local network clients; each client can be a member of one or several groups. The same policy can be applied to different groups. Note: During installation, the application automatically creates the default user and default user group, because at least one user group is required for Kaspersky...
Page 35
® Using Kaspersky Anti-Virus If a client is a member of several groups, it is scanned for viruses using settings for the group with the mildest rules of anti-virus protection. An example is a client belonging both to the Accountant Department group for which these chunks of data are scanned, and to the Administrators group for which these chunks of data are excluded from scanning.
Page 36
Kaspersky Anti-Virus 5.6 for Microsoft ISA Server 2004/2006 Standard Edition In the next dialog box (Fig. 16), click Add clients … In the Clients dialog box, either select a client from the list of existing clients or create a new client by clicking New… If you select New…, you will see the Client Properties dialog box.
Page 37
® Using Kaspersky Anti-Virus Figure 16. Adding clients to a new group Note: The newly created group is assigned to the default policy. To change the description and names of clients in a group: Select the required group in the Manage groups of Kaspersky Anti-Virus clients (Fig.
Kaspersky Anti-Virus 5.6 for Microsoft ISA Server 2004/2006 Standard Edition Figure 18. The Clients tab Figure 17. The General tab To delete a group: Select the required group in the Manage groups of Kaspersky Anti- Virus clients dialog box (Fig. 14) and click Delete a group. 4.2.3.
Page 39
® Using Kaspersky Anti-Virus To switch to the list of policies: ® Select Manage policies in the Kaspersky Anti-Virus main window (Figure 7). You will see the Manage Kaspersky Anti-Virus policies di- alog box (Fig. 19). Figure 19. The Manage Kaspersky Anti-Virus policies dialog box To create a new policy: Click Create a policy.
Page 40
Kaspersky Anti-Virus 5.6 for Microsoft ISA Server 2004/2006 Standard Edition Figure 20. Creating a new policy Figure 21. Adding a group of clients...
Page 41
® Using Kaspersky Anti-Virus Figure 22. Adding trusted servers Figure 23. Adding an object type...
Page 42
Kaspersky Anti-Virus 5.6 for Microsoft ISA Server 2004/2006 Standard Edition To edit policy settings: In the Manage Kaspersky Anti-Virus policies dialog box (Fig. 19), se- lect the policy and click Edit policy settings. On the General tab of the new dialog box (Fig. 24), you can rename the policy and change its description.
® Using Kaspersky Anti-Virus Figure 26. The Servers tab Figure 27. The Object Types tab To delete a policy: In the Manage Kaspersky Anti-Virus policies dialog box (Fig. 19), se- lect a policy and click Delete a policy. Note: After a policy is deleted, all groups of clients assigned to this policy are automati- cally assigned to the default policy.
Page 44
Kaspersky Anti-Virus 5.6 for Microsoft ISA Server 2004/2006 Standard Edition Server IP address. Subnet. Range of IP addresses. Figure 28. Adding a trusted server Note: To delete a trusted server from the list, click the corresponding button on the Servers tab (see Figure 26). 4.2.3.2.
® Using Kaspersky Anti-Virus Note: The list of objects excluded of scans contains BMP, GIF, and PNG files by de- fault. If you do not want Kaspersky Anti-Virus to scan objects in streaming trans- fers of audio and video broadcasts, exclude from the scanning scope objects of these types: Adobe Flash video, Windows Media Streaming Protocol object and QuickTime video.
Page 46
Kaspersky Anti-Virus 5.6 for Microsoft ISA Server 2004/2006 Standard Edition Figure 30. Configuring update settings To configure updating settings for downloading updates from the Internet: In the application main window, select Edit Kaspersky Anti-Virus properties and, in the Properties of Kaspersky Anti-Virus for Microsoft ISA Server dialog box, select the Updating tab.
Page 47
® Using Kaspersky Anti-Virus In the Use HTTP proxy part, enter the HTTP proxy parameters if such a proxy is used in your system: Select Use local proxy of the ISA server to use a local proxy of the Microsoft ISA server to update the anti-virus database via the Internet.
Kaspersky Anti-Virus 5.6 for Microsoft ISA Server 2004/2006 Standard Edition 4.3.1. Scheduled updating of the anti-virus database To enable automatic updating of your anti-virus database, check the Automati- cally update anti-virus databases box. The anti-virus database is updated as often as set by the ISA Server administra- tor.
® Using Kaspersky Anti-Virus <h1>Kaspersky Anti-Virus for Microsoft ISA Server</h1> <p>The requested URL "%URL%" is infected with %VIRUSNAME% virus</p> </body> </html> The following extensible variables are used in the message text: %URL% – the URL of the Internet resource requested by the client. %VIRUSNAME% –...
Kaspersky Anti-Virus 5.6 for Microsoft ISA Server 2004/2006 Standard Edition The test virus was specially designed by the organization (The Euro- pean Institute for Computer Antivirus Research) for testing anti-virus products. The test “virus” IS NOT ACTUALLY A VIRUS because it does not contain code that can really harm your computer.
Page 51
® Using Kaspersky Anti-Virus From the Performance Object drop-down list, select the KAV for ISA object. A list of parameters currently logged appears in the lower left field: Select All counters if you want to view statistics of all the pa- ®...
Kaspersky Anti-Virus 5.6 for Microsoft ISA Server 2004/2006 Standard Edition HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsNT \CurrentVersion\Perflib HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Con trol\SecurePipeServers\Winreg Read and write access to the following key: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Ser vices\Anti-Virus KL for Microsoft ISA System privileges (assigned from Control Panel -> Adminis- trative tools -> Local Security Policy -> Security settings -> Local Policies ->...
® Using Kaspersky Anti-Virus source, or Infected object detected in HTTP traffic. Kaspersky Anti-Virus critical events are added to the existing list of critical events after the application is in- stalled on the server. You can customize how you will be notified upon such events.
Page 54
Kaspersky Anti-Virus 5.6 for Microsoft ISA Server 2004/2006 Standard Edition ® virusDATE.log – Kaspersky Anti-Virus log file that stores information about malicious objects detected during scans. You can custom the report detail level on the Diagnostics tab of the Server Properties dialog box (see Figure 34).
® Using Kaspersky Anti-Virus Minimum – Record only main events, for example, application startup and shutdown, etc. Medium – In addition to main event, log additional events describing ® Kaspersky Anti-Virus performance in more detail (for example, errors when connecting to update servers). Maximum –...
Kaspersky Anti-Virus 5.6 for Microsoft ISA Server 2004/2006 Standard Edition ning completes thus increasing the risk of harmful code penetration into the network. Data not sent to the client before scan completes. Decreasing the value of that option increases the risk of virus penetration when a file is being scanned and transmitted at the same time.
® Using Kaspersky Anti-Virus Warning! Even if one manually installs the fresh anti-virus database after the application license expires, Kaspersky Anti-Virus will treat this action as a violation of the license agreement. As the result, anti-virus scanning will be disabled! If you fail to find the license key in the distribution kit, contact the distributor who sold you this copy of the product.
Page 58
Kaspersky Anti-Virus 5.6 for Microsoft ISA Server 2004/2006 Standard Edition Figure 35. Managing license keys After the license key is added, the following information will be dis- played: license key status; license key type; license owner; license expiry date; license key serial number; number of protected computers If you want the program to send you reminders about the expiry of the license: On the Licensing tab (see Figure 35), enter the corresponding number...
® Using Kaspersky Anti-Virus Warning! You cannot install more than two license keys! 4.8.2. Renewing your license If your license has expired, you need to renew it to restore the functionality of the ® program, i. e., you must purchase a new license key. Kaspersky Anti-Virus will not update the anti-virus database until your license is renewed, and, hence we do not guarantee 100% protection from viruses.
Kaspersky Anti-Virus 5.6 for Microsoft ISA Server 2004/2006 Standard Edition Figure 36. Managing license keys 4.8.3. Removing a license key During installation of a new license key, you can manually remove the expired key by clicking the corresponding button on the Licensing tab (Fig. 36). If you have installed two keys –...
CHAPTER 5. FREQUENTLY ASKED QUESTIONS Question: Is this possible to use Kaspersky Anti-Virus with anti-virus software supplied by other manufacturers? In order to avoid conflicts we recommend that you uninstall ant-virus software of other manufacturers prior to installation of Kaspersky Anti- Virus.
Page 62
Kaspersky Anti-Virus 5.6 for Microsoft ISA Server 2004/2006 Standard Edition Question: Why do I need the license key ? Will my Kaspersky Anti-Virus® work without it? ® No, Kaspersky Anti-Virus does not work without a license key. If you are still deciding whether or not to purchase Kaspersky Anti- ®...
Page 63
Frequently Asked Questions The product works correctly using a test virus (see section 4.5 on page 49). If the test virus is not recognized as an infected object, it is probably loaded from the local cache of your browser. In this case, run a browser command that forcedly loads files from the server bypassing browser cache.
Page 64
Kaspersky Anti-Virus 5.6 for Microsoft ISA Server 2004/2006 Standard Edition c. Make sure that your server can connect to the Kaspersky Lab update servers. For example, configure the Internet options of Internet Explorer on the same computer where Kaspersky Anti- Virus is installed and open any web page.
APPENDIX A. GLOSSARY This documentation uses some terms specific to anti-virus protection. The glos- sary is a list of definitions of these terms. The glossary entries are arranged in alphabetical order for ease of use. А Administrator Console – an application providing a user interface for ad- ®...
APPENDIX B. KASPERSKY LAB Founded in 1997, Kaspersky Lab has become a recognized leader in information security technologies. It produces a wide range of high-performance data securi- ty software including anti-virus, anti-spam and anti-hacking systems. Kaspersky Lab is an international company. Headquartered in the Russian Fed- eration, the company has offices in the United Kingdom, France, Germany, Ja- pan, the Benelux countries, China, Poland, Romania and the USA (California).
Page 67
Appendix B If you have any questions, you can contact our dealers or contact Kaspersky Lab directly. Detailed consultations are provided by phone or e-mail. You will receive full and comprehensive answers to any question. Address: Russia, 123060, Moscow, 1-st Volokolamsky Proezd, 10, Building 1 Tel., Fax: +7 (495) 797-87-00, +7 (495) 645-79-39,...
Page 68
Kaspersky Anti-Virus 5.6 for Microsoft ISA Server 2004/2006 Standard Edition WWW: http://www.kaspersky.com/ http://www.viruslist.com...
APPENDIX C. LICENSE AGREEMENT Standard End User License Agreement NOTICE TO ALL USERS: CAREFULLY READ THE FOLLOWING LEGAL AGREEMENT (“AGREEMENT”), FOR THE LICENSE OF KASPERSKY ANTI- VIRUS (“SOFTWARE”) PRODUCED BY KASPERSKY LAB (“KASPERSKY LAB”). IF YOU HAVE PURCHASED THIS SOFTWARE VIA THE INTERNET BY CLICKING THE ACCEPT BUTTON, YOU (EITHER AN INDIVIDUAL OR A SINGLE ENTITY) CONSENT TO BE BOUND BY AND BECOME A PARTY TO THIS AGREEMENT.
Page 70
Kaspersky Anti-Virus 5.6 for Microsoft ISA Server 2004/2006 Standard Edition All references to “Software” herein shall be deemed to include the software acti- vation code with which you will be provided by Kaspersky Lab as a part of the Kaspersky Anti-Virus. 1.
Page 71
Appendix C 1.1.5 You shall not make error corrections to, or otherwise modify, adapt, or translate the Software, nor create derivative works of the Software, nor permit any third party to copy (other than as expressly permitted herein). 1.1.6 You shall not rent, lease or lend the Software to any other person, nor transfer or sub-license your license rights to any other person.
Page 72
Kaspersky Anti-Virus 5.6 for Microsoft ISA Server 2004/2006 Standard Edition also provided to you by Kaspersky Lab with this Agreement. It shall be at the absolute discretion of Kaspersky Lab whether or not you have satisfied this condition for the provision of Support Services. Support Services shall become available after Software activation.
Page 73
Appendix C erwise make available such confidential information in any form to any third party without the prior written consent of Kaspersky Lab. You shall implement reason- able security measures to protect such confidential information, but without limi- tation to the foregoing shall use best endeavours to maintain the security of the activation code.
Page 74
Kaspersky Anti-Virus 5.6 for Microsoft ISA Server 2004/2006 Standard Edition terms as to satisfactory quality, fitness for purpose or as to the use of reasonable skill and care). 6. Limitation of Liability. Nothing in this Agreement shall exclude or limit Kaspersky Lab’s liability for (a) the tort of deceit, (b) death or personal injury caused by its breach of a common law duty of care or any negligent breach of a term of this Agreement, or (c) any other liability which cannot be excluded by...
Page 75
Appendix C 7. This Agreement contains the entire understanding between the parties with respect to the subject matter hereof and supersedes all and any prior under- standings, undertakings and promises between you and Kaspersky Lab, whether oral or in writing, which have been given or may be implied from anything written or said in negotiations between us or our representatives prior to this Agreement and all prior agreements between the parties relating to the matters aforesaid shall cease to have effect as from the Effective Date.
Need help?
Do you have a question about the ANTI-VIRUS 5.6 - FOR MICROSOFT ISA SERVER 2004-2006 STANDARD EDITION and is the answer not in the manual?
Questions and answers