27.11.2012 Views

IronPort - Configuration Guide - AsyncOS 7.6.1

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

OL-25136-01<br />

Anti-Virus<br />

Anti-Virus Scanning<br />

Evaluation Key<br />

CHAPTER<br />

8<br />

The Cisco <strong>IronPort</strong> appliance includes integrated virus scanning engines from Sophos, Plc and McAfee,<br />

Inc. You can obtain license keys for the Cisco <strong>IronPort</strong> appliance to scan messages for viruses using one<br />

or both of these virus scanning engines.<br />

You can configure the appliance to scan messages for viruses (based on the matching incoming or<br />

outgoing mail policy), and, if a virus is found, to perform different actions on the message (including<br />

“repairing” the message of viruses, modifying the subject header, adding an additional X-header,<br />

sending the message to an alternate address or mailhost, archiving the message, or deleting the message).<br />

If enabled, virus scanning is performed in the “work queue” on the appliance, immediately after<br />

Anti-Spam scanning. (See Understanding the Email Pipeline, page 4-1.)<br />

By default, virus scanning is enabled for the default incoming and outgoing mail policies.<br />

Anti-Virus Scanning, page 8-1<br />

Sophos Anti-Virus Filtering, page 8-2<br />

McAfee Anti-Virus Filtering, page 8-4<br />

Enabling Virus Scanning and Configuring Global Settings, page 8-6<br />

Configuring Virus Scanning Actions for Users, page 8-8<br />

Testing Virus Scanning, page 8-18<br />

You can configure your Cisco <strong>IronPort</strong> appliance to scan for viruses using the McAfee or Sophos<br />

anti-virus scanning engines.<br />

The McAfee and Sophos engines contain the program logic necessary to scan files at particular points,<br />

process and pattern-match virus definitions with data they find in your files, decrypt and run virus code<br />

in an emulated environment, apply heuristic techniques to recognize new viruses, and remove infectious<br />

code from legitimate files.<br />

Your Cisco <strong>IronPort</strong> appliance ships with a 30-day evaluation key for each available anti-virus scanning<br />

engine. You enable the evaluation key by accessing the license agreement in the System Setup Wizard<br />

or Security Services > Sophos/McAfee Anti-Virus pages (in the GUI) or running the antivirusconfig<br />

or systemsetup commands (in the CLI). Once you have accepted the agreement, the Anti-Virus scanning<br />

Cisco <strong>IronPort</strong> <strong>AsyncOS</strong> 7.6 for Email <strong>Configuration</strong> <strong>Guide</strong><br />

8-1

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!