27.11.2012 Views

IronPort - Configuration Guide - AsyncOS 7.6.1

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Chapter 8 Anti-Virus<br />

OL-25136-01<br />

Note For information about how and when anti-virus scanning is applied, see Email Pipeline and<br />

Security Services, page 4-6.<br />

Retrieving Anti-Virus Updates via HTTP<br />

By default, the Cisco <strong>IronPort</strong> appliance is configured to check for updates every 5 minutes. For the<br />

Sophos and McAfee anti-virus engines, the server updates from a dynamic website.<br />

The system does not timeout on updates as long as the update is actively downloading to the appliance.<br />

If the update download pauses for too long, then the download times out.<br />

The maximum amount of time that the system waits for an update to complete before timing out is a<br />

dynamic value that is defined as 1 minute less than the anti-virus update interval (defined on Security<br />

Services > Service Updates). This configuration value aids appliances on slower connections while<br />

downloading large updates that may take longer than 10 minutes to complete.<br />

Monitoring and Manually Checking for Updates<br />

Once you have accepted the license agreement and configured the global settings, you can use the<br />

Security Services > Sophos or McAfee Anti-Virus page (GUI) or the antivirusstatus command (CLI)<br />

to verify that you have the latest anti-virus engine and identity files installed, and to confirm when the<br />

last update was performed.<br />

You can also manually perform updates. From the Security Services > Sophos or McAfee Anti-Virus<br />

page, click Update Now in the Current McAfee/Sophos Anti-Virus Files table. The appliance checks for<br />

and downloads the latest updates.<br />

Figure 8-1 Manually Checking for Sophos Updates<br />

In the CLI, use the antivirusstatus command to check the status of your virus files and<br />

antivirusupdate command to manually check for updates:<br />

example.com> antivirusstatus<br />

Choose the operation you want to perform:<br />

- MCAFEE - Display McAfee Anti-Virus version information<br />

- SOPHOS - Display Sophos Anti-Virus version information<br />

> sophos<br />

SAV Engine Version 3.2.07.286_4.58<br />

IDE Serial 0<br />

Last Engine Update Base Version<br />

Last IDE Update Never updated<br />

Cisco <strong>IronPort</strong> <strong>AsyncOS</strong> 7.6 for Email <strong>Configuration</strong> <strong>Guide</strong><br />

8-7

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!