333
Preventing attacks
Protecting your network resources from virus infections
Protecting your network resources from virus infections
The security gateway lets you configure antivirus scanning and filtering policies. You can perform
antivirus scanning on any traffic using the FTP, HTTP, POP3, and SMTP protocols. Some scanning and
filtering policy features differ depending on the protocol that you are using.
This section covers the following topics:
■
■
Preventing denial of service attacks
■
Blocking files that cannot be scanned
■
■
Avoiding potential session time-out errors
■
Blocking mail attachments that are known threats
■
Responding to virus detections
■
Adding antivirus protection to a rule
■
Troubleshooting antivirus protection
About antivirus scanning
The security gateway features all of the virus scanning technologies that are available in Symantec
antivirus products. The security gateway antivirus scanner detects viruses, worms, and Trojan horses
in all major file types. The security gateway also includes a decomposer that handles most compressed
and archive file formats and nested levels of files.
The security gateway antivirus scanner also detects mobile code such as Java™, ActiveX
®
, and stand-
alone script-based threats. The security gateway uses Symantec antivirus technologies for heuristic
detection of new or unknown viruses, to provide protection from new classes of viruses automatically
through LiveUpdate, and to detect polymorphic viruses.
If you would like to know whether the security gateway or any other Symantec product protects
against a specific virus, visit the Symantec Security Response™ Web site at:
http://securityresponse.symantec.com
For additional background information, see the following topics:
■
“Ways to protect your environment from threats”
■
“Optimizing antivirus scanning performance”
■
“Avoiding session time-outs when downloading large files using data comforting”
■
“Responding to antivirus threats”
■
“Keeping your antivirus protection up-to-date”
Ways to protect your environment from threats
The security gateway offers settings to help prevent denial of service attacks, which are caused by
large container files or files that contain multiple, embedded compressed files. You can also protect
your security gateway by configuring settings to block files that cannot be scanned.
You can use some scanning and blocking policy settings during a virus outbreak to further protect your
security gateway. Once you have information on the characteristics of a new virus, you can use this
information to block the infected attachment or email immediately, before virus definitions for the
new virus are posted. Or, for maximum coverage, you can scan all file types rather than limiting the
file types that are scanned for viruses.
Summary of Contents for Security 5600 Series, Security 5400 Series,Clientless VPN 4400 Series
Page 76: ...76 Managing administrative access Enabling SSH for command line access to the appliance...
Page 242: ...242 Defining your security environment Controlling full application inspection of traffic...
Page 243: ...243 Defining your security environment Controlling full application inspection of traffic...
Page 269: ...268 Limiting user access Authenticating using Out Of Band Authentication OOBA...
Page 373: ...372 Preventing attacks Enabling protection for logical network interfaces...
Page 509: ...508 Generating reports Upgrade reports...
Page 553: ...552 Advanced system settings Configuring advanced options...
Page 557: ...556 SSL server certificate management Installing a signed certificate...
Page 861: ...860 Index...