background image

Configuration

52

AntiVir WebGate

Avira GmbH

Summary of Contents for ANTIVIR UNIX WEBGATE

Page 1: ...User Manual Avira AntiVir WebGate Avira WebGate Suite www avira com...

Page 2: ...er ICAP Interface 32 4 5 Configuration Files 34 4 5 1Configuration File avwebgate conf 34 4 5 2Configuration File avupdater conf 41 4 5 3Configuration File avwebgate acl 42 4 6 Configuration Script 43...

Page 3: ...2 AntiVir WebGate Avira GmbH Chapter 8 Appendix 79 8 1 Glossary 79 8 2 Further Information 80 8 3 Golden Rules for Protection Against Viruses 81...

Page 4: ...closed in this manual all the information you need about AntiVir WebGate and it will guide you step by step through installation configuration and operation of the software The appendix contains a Glo...

Page 5: ...Operating Working with AntiVir WebGate Reactions when detecting viruses and unwanted programs 6 Graphical User Interface GUI General information about GUI Operation and configuration of AntiVir WebGa...

Page 6: ...onent Select all Elements of the software interface such as menu items window titles and buttons in dialog windows http www avira com URLs Signs and Symbols Page 4 Cross reference within the document...

Page 7: ...About this Manual 6 AntiVir WebGate Avira GmbH...

Page 8: ...ore AntiVir WebGate also scans the entire outgoing traffic Usually company computers access the Internet indirectly via a proxy server AVIRA WebGate co operates with the proxy server and completes it...

Page 9: ...ions for the administrator protocol warnings reports sending email warnings SMTP Self Integrity Program Check which ensures the antivirus system is operating correctly Optional user friendly graphic i...

Page 10: ...ll Version license the Comfort Pack includes z Every three months free delivery of a boot CD ROM with the AntiVir Rescue System and all updated AntiVir products z Complete installation manual printed...

Page 11: ...bGate allows clients to filter outgoing requests based on URL categories such as Violence Gambling Erotic etc To determine the categories for a certain URL the Web Access and Content Control library i...

Page 12: ...r WebGate Using the Graphical User Interface Page 18 3 1 Choosing the WebGate Computer Depending on network and hardware configuration there are more possibilities for choosing an AntiVir WebGate comp...

Page 13: ...v key This license file contains information regarding the range and period of the license Without the license file AntiVir WebGate runs only as Demo Version with restricted features Purchasing the Li...

Page 14: ...z Optionally installs Internet Updater z Optionally installs WebGate GUI z Optionally configures the automatic start of AntiVir WebGate or of the Internet Updater For the first installation you must...

Page 15: ...e automatic system start is configured Installation without update daemon If you want to install the Internet update daemon later or never at all Type N or press Enter 1 installing AntiVir Engine copy...

Page 16: ...ng script avwebgate to usr lib AntiVir done creating usr lib AntiVir templates done creating usr lib AntiVir templates examples done creating usr lib AntiVir templates examples en done creating usr li...

Page 17: ...f not found copying etc avwebgate conf gui to etc avwebgate conf done copying common gui files to usr lib AntiVir gui done copying platform dependant gui files to usr lib AntiVir gui done copying scri...

Page 18: ...ee Configuration Page 25 z Later installation of some components e g Internet Updater or GUI z Activating or deactivating the automatic start of AntiVir WebGate or Internet Updater AntiVir WebGate rei...

Page 19: ...which enables the operation and configuration of AntiVir WebGate The graphical installation routine for AntiVir WebGate runs only on Linux It requires Java 1 4 0 or higher 3 The program file is unpac...

Page 20: ...gs z WebGate Main Program and AntiVir AntiVir Search Engine are installed in the directory usr lib AntiVir z The automatic Internet Updater is not installed z GUI support is activated z WebGate will s...

Page 21: ...Select Yes or No and click Next Then you must specify if you want to install the automatic Internet Updater If you wish to install the Internet Updater Select Yes and click Next in this case you are a...

Page 22: ...21 Select the license file with Choose and click Next The next window asks if WebGate should start automatically by computer boot Select Yes or No and click Next An optional question asks if the Inte...

Page 23: ...further instructions Click Install The program will be installed GUI only Choose this option if you wish to install only the GUI Select GUI only and click Next The GUI is installed in the following d...

Page 24: ...ation Following any installation type you selected a window will list the performed installation steps Click Next You will see the following window If you want to start the GUI directly Activate the o...

Page 25: ...Installation 24 AntiVir WebGate Avira GmbH...

Page 26: ...etwork setting z In Monitoring FTP Traffic Page 30 is a description of integrating WebGate as FTP proxy z Integration over ICAP Interface Page 32 presents the integration of WebGate over ICAP interfac...

Page 27: ...b AntiVir configantivir see Configuration Script Page 43 GUI avwebgate conf can be easily configured using the Configuration options in the graphical user interface GUI see Configuring AntiVir WebGate...

Page 28: ...om the Client s point of view WebGate is functioning as a proxy server Make the following settings in avwebgate conf example HTTPPort 8080 Configure the browser according to the Clients For Proxy Serv...

Page 29: ...es through the proxy server to the Internet and scans the answers from the Internet which are received through the proxy server The access to infected files from a Website is blocked and only not infe...

Page 30: ...make any changes on the Clients It is also possible to install WebGate on a computer other than the proxy server The settings must be done accordingly In this network configuration a Client could also...

Page 31: ...WebGate is installed on the proxy server machine Make sure that WebGate and the proxy server do not respond on the same server ports such as is the case in the above example WhenaClientasksfordata whi...

Page 32: ...r name foo and the password bar ftp 192 168 0 1 2121 Connected to 192 168 0 1 220 AntiVir WebGate FTP proxy Login with user name host port Name 192 168 0 1 user foo 10 0 0 1 331 Password required for...

Page 33: ...WebGate can still scan and block incoming RESPMOD and outgoing REQMOD files In avwebgate conf you must set the port through which WebGate will communicate with the ICAP Client ICAPPort 1344 Scanning...

Page 34: ...returned to the ICAP Client and from there it is sent to the destination server If the request is blocked i e in case of a virus detection WebGate generates an HTML page based on the corresponding HTM...

Page 35: ...Client or proxy computers There are various setups needed according to the configuration see Monitoring HTTP Traffic Page 26 The default is HTTPPort host_ip_or_name 8080 We recommend not to allow acce...

Page 36: ...ill be separated by a comma or a whitespace AllowedHTTPConnectPorts 443 563 Max Connections Maximum number of connections allowed The maximum number of simultaneous connections allowed to run through...

Page 37: ...r proxy HTTPProxyPort 8080 HTTPProxyUsername username HTTPProxyPassword password FTPProxy Settings for FTP proxy server If WebGate serves as FTP proxy see FTPPort option you can set a parent proxy for...

Page 38: ...ttings for ArchiveMaxSize ArchiveMaxRecursion and ArchiveMaxRatio BlockSuspiciousArchive 0 Block Encrypted Archive Blocking password protected archives If this option is activated WebGate blocks passw...

Page 39: ...e EmailTo root localhost AddX ForwardedFor Header Header analysis In case of a proxy chain network a downstream proxy server can make no analysis based on the Client s IP address because it sees all r...

Page 40: ...ts 21 80 1025 65535 If you do not specify any ports the access is not restricted If you specify at least one port the access is permitted only on the entered ports Any other port has no access AclConf...

Page 41: ...csMacro yes Heuristics Level Win32 Heuristics Sets the detection level of Win32 Heuristics available values are 0 off 1 low 2 medium and 3 high Default HeuristicsLevel 2 GUISupport Support over graphi...

Page 42: ...ult setting You must enter the full path to the logfile in order to use this option LogTo var log avupdater log AutoUpdate Update scheduler The security software can check regularly for updates online...

Page 43: ...is usually not necessary For security reasons both settings are by default deactivated Updater Keeps Backups The Internet Updater replaces installed files with newer versions when updates are availabl...

Page 44: ...le the current ones are shown as default If you want to keep one of the current settings Press Enter If you want to change a setting Type the new value and confirm with Enter In the end a summary of t...

Page 45: ...re at any time There are two possible methods to configure automatic AntiVir updates 1 You can use the Internet Updater which was delivered together with your AntiVir program and is easy to configure...

Page 46: ...h Enter all remaining settings The Internet connection is now configured If this machine is sitting behind an HTTP proxy server you will need to config ure AntiVir with the appropriate proxy settings...

Page 47: ...r manually Type usr lib AntiVir avupdater stop If you want to check the current status of the Internet Updater Type usr lib AntiVir avupdater status Configuring Automatic Updates in avupdater conf Upd...

Page 48: ...n configantivir usr lib AntiVir configantivir First it asks you how often you need AntiVir to check for updates Type n if you do not want automatic updates AntiVir is equipped with an Internet Update...

Page 49: ...more configuration possibilities than with the Internet Updater Example Enter the following cron job in etc crontab 45 2 root usr lib AntiVir antivir update q This command activates updates every 2 ho...

Page 50: ...PGP key into your key ring gpg import antivir gpg Display the fingerprint of the key to check if it really is the AntiVir PGP key gpg fingerprint build avira com The 40 character fingerprint is displa...

Page 51: ...vailable templates HTML Templates Template Meaning alert html Displayed when an alert is found by AvWebGate blocked html Displayed when AvWebGate has blocked a suspicious file using various block sett...

Page 52: ...h a Test Virus Start WebGate usr lib AntiVir avwebgate start Type the following URL in your Web browser http www eicar org Read the information about the test virus eicar com Download the test virus o...

Page 53: ...Configuration 52 AntiVir WebGate Avira GmbH...

Page 54: ...d stop procedure of WebGate from the console z In Procedures when Detecting Viruses or Unwanted Programs Page 54 you can learn what you should do in case of an infection in your network 5 1 Starting a...

Page 55: ...ou should however follow these guidelines Try to detect the way the infection sneaked on your system Perform targeted scanning on the data storage that might be infected Inform your team superiors or...

Page 56: ...ation Type as root usr sbin usermod G group1 group2 group3 antivir username group1 group3 are the groups to which the user belongs username is the name of the user To set the groups for a user Type us...

Page 57: ...st be installed in usr lib AntiVir z You must have a COMMERCIAL license for AntiVir WebGate antivir version z The parameter GuiSupport must be set in avwebgate conf z The user must belong to the antiv...

Page 58: ...yellow text WebGate will be restarted More WebGates In case there are more WebGates in the network different situations can be displayed in the following format example 1 2 1 1 Meaning z 1 WebGate is...

Page 59: ...s not stopped WebGate z Realtime view to display the graphical Realtime view z Logfile to switch to Logfile table window z Configuration to open the Configuration window z Load configuration to load a...

Page 60: ...figuration see Basic WebGate Settings Page 63 The y axis changes automatically according to the current value levels Table with description The text description is divided in five columns z Computer s...

Page 61: ...ayed log levels and the log level used by WebGate Four buttons appear on the bottom of the window Settings Rows Load new and More Settings Press Settings An additional area appears in the Logfile wind...

Page 62: ...WebGate Start Select the menu option WebGate Start WebGate Stop Select the menu option WebGate Stop WebGate Restart Select the menu option WebGate Restart WebGate Changing the Time Intervals Set the t...

Page 63: ...n Files Page 34 AntiVir GUI also applies to other AntiVir products and in case you have more products installed on the same computer it displays the options according to the selected product When work...

Page 64: ...directory stores for example the files during scanning HTTP Port This entry sets the port on which WebGate communicates for HTTP connections with the Client computer or the proxy server It may need va...

Page 65: ...possibilities The entries are given in seconds z If the Client is a browser WebGate sends an HTML progress page which is updated at regular intervals The time interval is set with Refresh Interval z...

Page 66: ...Page 38 Activate Heuristics If you activate heuristics WebGate also traces unknown viruses You can set the detection level for Win32 Heuristics Quarantine Directory Enter the directory you want to st...

Page 67: ...P connections z Server Proxy server s hostname or IP The parameters are HTTPProxyServer and FTPProxyServer in avwebgate conf z Port Port for proxy server communication with WebGate The parameters are...

Page 68: ...smaller than the maximum size in Bytes The null value means no limit Default is 1 GB It corresponds to ArchiveMaxSize in avwebgate conf Maximum recursion When scanning recursive archives the level of...

Page 69: ...kSuspiciousArchive in avwebgate conf Block encrypted archives If activated this option blocks password protected archives It corresponds to BlockEncryptedArchive in avwebgate conf Block partial archiv...

Page 70: ...NG z 5 NOTICE z 6 INFO z 7 DEBUG For example LogLevel 4 means that the logfile contains all EMERGENCY ALERT CRITICAL ERROR and WARNING notifications NOTICE INFO and DEBUG messages will not be recorded...

Page 71: ...tiVir antivir gui Define the basic settings in Basic WebGate Settings Page 63 Define the extended settings If you are not sure about possible values for example the maximum number of connections allow...

Page 72: ...dater tab The Updater main window displays information about the Operating System and the Versions of the product engine PackLib and VDF A scroll text area describes the current Updater activity You c...

Page 73: ...Configuration to open the Configuration window Start Update to update WebGate Updater Logfile Window Click on the Logfile button OR Select the menu option Updater Logfile The Logfile window appears Lo...

Page 74: ...the number of Lines given 6 5 Configuring AntiVir Updater Using the GUI You can make the configuration settings for AntiVir Updater directly in the GUI AntiVir GUI also applies to other AntiVir produc...

Page 75: ...pdater conf are AutoUpdateEvery2Hours AutoUpdateDaily AutoUpdateTime Updater Proxy Settings HTTP Proxy Here you must set the HTTP connection for updates z Server update proxy server s hostname or IP z...

Page 76: ...yslog daemon You could specify an additional logfile by entering the full path For example var log avupdater log It corresponds to LogTo in avupdater conf Email AntiVir Updater is able to send emails...

Page 77: ...Graphical User Interface GUI 76 AntiVir WebGate Avira GmbH...

Page 78: ...chased AntiVir program Another optional service is the AntiVir Premium Support which offers you additionally to the scope of the AntiVir Classic Supports the possibility to reach competent partners at...

Page 79: ...e 78 AntiVir WebGate Avira GmbH 7 3 Contact Address Avira GmbH Lindauer Strasse 21 D 88069 Tettnang Germany Internet You can find further information about us and our products by visiting http www avi...

Page 80: ...nnection charging you at higher rates This can lead to huge phone bills AntiVir detects Dialers Engine The scanning module of AntiVir software Heuristic The systematic process of solving a problem usi...

Page 81: ...ric Multi Processing Unix SMP Unix version for computers with parallel processors SMTP Simple Mail Transfer Protocol protocol for email transport on the Internet syslog daemon A daemon used by program...

Page 82: ...g and during installation If there are other users connected to your computer you should set the following rules for protection against viruses Use a test computer for controlling downloads of new sof...

Page 83: ...rors excepted Content suject to change Issued Q4 2007 AntiVir is a registered trademark of the Avira GmbH All other brand and product names are trademarks or registered trademarks of their respective...

Reviews: