30.01.2015 Views

Administrator's Guide - Kerio Software Archive

Administrator's Guide - Kerio Software Archive

Administrator's Guide - Kerio Software Archive

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Antivirus control<br />

Warning:<br />

1. Antivirus control within WinRoute can only detect and block infected attachments.<br />

Attached files cannot be healed by this control!<br />

2. Within antivirus scanning, it is possible to remove only infected attachments, entire<br />

email messages cannot be dropped. This is caused by the fact that the firewall cannot<br />

handle email messages like mailservers do. It only maintains network traffic coming<br />

through. In most cases, removal of an entire message would lead to a failure in<br />

communication with the server and the client might attempt to send/download the<br />

message once again. Thus, one infected message might block sending/reception of any<br />

other (legitimate) mail.<br />

3. In case of SMTP protocol, only incoming traffic is checked (i.e. traffic from the Internet<br />

to the local network — incoming email at the local SMTP server). Checks of outgoing<br />

SMTP traffic (i.e. from the local network to the Internet) might cause problems with<br />

temporarily undeliverable email (for example in cases where the destination SMTP<br />

server uses so called greylisting).<br />

To check also outgoing traffic (e.g. when local clients connect to an SMTP server without<br />

the local network), define a corresponding traffic rule using the SMTP protocol inspector.<br />

For details, see chapter 14.2.<br />

Advanced parameters and actions that will be taken when a virus is detected can be set in the<br />

Email scanning tab.<br />

In the Specify an action which will be taken with attachments... section, the following actions<br />

can be set for messages considered by the antivirus as infected:<br />

• Move message to quarantine — untrustworthy messages will be moved to a special<br />

directory on the <strong>Kerio</strong> Control host. The <strong>Kerio</strong> Control administrator can try to heal<br />

infected files and later send them to their original addressees.<br />

The quarantine subdirectory under the <strong>Kerio</strong> Control directory is used for the<br />

quarantine<br />

(the typical path is C:\Program Files\<strong>Kerio</strong>\WinRoute Firewall\quarantine)<br />

Messages with untrustworthy attachments are saved to this directory under names<br />

which are generated automatically by WinRoute. Each filename includes information<br />

about protocol, date, time and the connection number used for transmission of the<br />

message.<br />

• Prepend subject message with text — use this option to specify a text to be attached<br />

before the subject of each email message where at least one infected attachment is<br />

found. This text informs the recipient of the message and it can be also used for<br />

automatic message filtering.<br />

200

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!