30.01.2015 Views

Administrator's Guide - Kerio Software Archive

Administrator's Guide - Kerio Software Archive

Administrator's Guide - Kerio Software Archive

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Chapter 14<br />

Antivirus control<br />

<strong>Kerio</strong> Control provides antivirus check of objects (files) transmitted by HTTP, FTP, SMTP and<br />

POP3 protocols. In case of HTTP and FTP protocols, the firewall administrator can specify<br />

which types of objects will be scanned.<br />

<strong>Kerio</strong> Control is also distributed in a special version which includes integrated Sophos<br />

antivirus. Besides the integrated module, <strong>Kerio</strong> Control also supports many external<br />

antiviruses of third parties. The antivirus license must meet the conditions of the producer<br />

(usually the same or higher number of users of the licensed version of <strong>Kerio</strong> Control or<br />

a special server license).<br />

<strong>Kerio</strong> Control allows to use both the integrated Sophos antivirus and a selected external<br />

antivirus. In such a case, transferred files are checked by both antiviruses (so called dual<br />

antivirus control). This feature reduces the risk of letting in a harmful file.<br />

However, using of two antiviruses at a time also decreases the speed of firewall’s performance.<br />

It is therefore highly recommended to consider thoroughly which method of antivirus check<br />

should be used and to which protocols it should be applied and, if possible and desired, to try<br />

the configuration in the trial version of <strong>Kerio</strong> Control before purchasing a license.<br />

Note:<br />

1. However, supported external antiviruses as well as versions and license policy of<br />

individual programs may change as the time flows. For up-to-date information please<br />

refer to (http://www.kerio.com/firewall).<br />

2. External Sophos Anti-Virus programs are not supported by <strong>Kerio</strong> Control.<br />

14.1 Conditions and limitations of antivirus scan<br />

Antivirus check of objects transferred by a particular protocol can be applied only to<br />

traffic where a corresponding protocol inspector which supports the antivirus is used (see<br />

chapter 15.3). This implies that the antivirus check is limited by the following factors:<br />

• Antivirus check cannot be used if the traffic is transferred by a secured channel<br />

(SSL/TLS). In such a case, it is not possible to decipher traffic and separate transferred<br />

objects.<br />

• Within email antivirus scanning (SMTP and POP3 protocols), the firewall only removes<br />

infected attachments — it is not possible to drop entire email messages. In case of<br />

SMTP protocol, only incoming traffic is checked (i.e. traffic from the Internet to the<br />

local network — incoming email at the local SMTP server). Check of outgoing traffic<br />

causes problems with temporarily undeliverable email.<br />

190

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!