background image

Appendix

Avira GmbH

AntiVir WebGate

79

8

Appendix

8.1

Glossary

Item

Meaning

Backdoor (BDC)

A backdoor is a program infiltrated in order to steal data from the 
computer, without the user’s knowledge. This program is manipulated 
by third-parties using a remote backdoor-control software, over the 
Internet or network.
AntiVir detects backdoor-control programs.

cron (daemon)

A daemon which starts other programs on specified times.

Daemon

A background process for administration on Unix systems. On average, 
there are about a dozen daemons running on a computer. These 
processes usually start up and shut down with the computer.

Demo version

Without a license file, AntiVir WebGate runs as demo version and it 
only reports the test virus EICAR. It will not block the access to 
infected files. The update function is not available.

Dialer

Paid dialing program. When installed on your computer, this program 
builds a Premium Rate Number Internet connection, charging you at 
higher rates. This can lead to huge phone bills.
AntiVir detects Dialers.

Engine

The scanning module of AntiVir software.

Heuristic

The systematic process of solving a problem using general and specific 
rules drawn from previous experience. The solution is however not 
guaranteed.
AntiVir uses a heuristic process for detecting unknown macro viruses. 
When typical virus-like functions are found, the respective macro is 
classified as "suspicious".

Kernel

The base component of a Unix operating system, which performs 
elementary functions (e.g. memory and process administration)

Logfile

also: Report file. A file containing reports generated by the program at 
run-time, when a certain event occurs.

Malware

Generic term for "foreign bodies" of any type. These can be 
interferences such as viruses or other software, which the user 
generally considers as unwanted (see also Unwanted Programs).

PMS (Possible 
Malicious Software)

Software that does not usually harm the computer. It is programmed 
to harm other users.
For example, Mail bombs: with such a program, the victim can be 
attacked by thousands of emails.
AntiVir detects PMS.

Содержание ANTIVIR UNIX WEBGATE

Страница 1: ...User Manual Avira AntiVir WebGate Avira WebGate Suite www avira com...

Страница 2: ...er ICAP Interface 32 4 5 Configuration Files 34 4 5 1Configuration File avwebgate conf 34 4 5 2Configuration File avupdater conf 41 4 5 3Configuration File avwebgate acl 42 4 6 Configuration Script 43...

Страница 3: ...2 AntiVir WebGate Avira GmbH Chapter 8 Appendix 79 8 1 Glossary 79 8 2 Further Information 80 8 3 Golden Rules for Protection Against Viruses 81...

Страница 4: ...closed in this manual all the information you need about AntiVir WebGate and it will guide you step by step through installation configuration and operation of the software The appendix contains a Glo...

Страница 5: ...Operating Working with AntiVir WebGate Reactions when detecting viruses and unwanted programs 6 Graphical User Interface GUI General information about GUI Operation and configuration of AntiVir WebGa...

Страница 6: ...onent Select all Elements of the software interface such as menu items window titles and buttons in dialog windows http www avira com URLs Signs and Symbols Page 4 Cross reference within the document...

Страница 7: ...About this Manual 6 AntiVir WebGate Avira GmbH...

Страница 8: ...ore AntiVir WebGate also scans the entire outgoing traffic Usually company computers access the Internet indirectly via a proxy server AVIRA WebGate co operates with the proxy server and completes it...

Страница 9: ...ions for the administrator protocol warnings reports sending email warnings SMTP Self Integrity Program Check which ensures the antivirus system is operating correctly Optional user friendly graphic i...

Страница 10: ...ll Version license the Comfort Pack includes z Every three months free delivery of a boot CD ROM with the AntiVir Rescue System and all updated AntiVir products z Complete installation manual printed...

Страница 11: ...bGate allows clients to filter outgoing requests based on URL categories such as Violence Gambling Erotic etc To determine the categories for a certain URL the Web Access and Content Control library i...

Страница 12: ...r WebGate Using the Graphical User Interface Page 18 3 1 Choosing the WebGate Computer Depending on network and hardware configuration there are more possibilities for choosing an AntiVir WebGate comp...

Страница 13: ...v key This license file contains information regarding the range and period of the license Without the license file AntiVir WebGate runs only as Demo Version with restricted features Purchasing the Li...

Страница 14: ...z Optionally installs Internet Updater z Optionally installs WebGate GUI z Optionally configures the automatic start of AntiVir WebGate or of the Internet Updater For the first installation you must...

Страница 15: ...e automatic system start is configured Installation without update daemon If you want to install the Internet update daemon later or never at all Type N or press Enter 1 installing AntiVir Engine copy...

Страница 16: ...ng script avwebgate to usr lib AntiVir done creating usr lib AntiVir templates done creating usr lib AntiVir templates examples done creating usr lib AntiVir templates examples en done creating usr li...

Страница 17: ...f not found copying etc avwebgate conf gui to etc avwebgate conf done copying common gui files to usr lib AntiVir gui done copying platform dependant gui files to usr lib AntiVir gui done copying scri...

Страница 18: ...ee Configuration Page 25 z Later installation of some components e g Internet Updater or GUI z Activating or deactivating the automatic start of AntiVir WebGate or Internet Updater AntiVir WebGate rei...

Страница 19: ...which enables the operation and configuration of AntiVir WebGate The graphical installation routine for AntiVir WebGate runs only on Linux It requires Java 1 4 0 or higher 3 The program file is unpac...

Страница 20: ...gs z WebGate Main Program and AntiVir AntiVir Search Engine are installed in the directory usr lib AntiVir z The automatic Internet Updater is not installed z GUI support is activated z WebGate will s...

Страница 21: ...Select Yes or No and click Next Then you must specify if you want to install the automatic Internet Updater If you wish to install the Internet Updater Select Yes and click Next in this case you are a...

Страница 22: ...21 Select the license file with Choose and click Next The next window asks if WebGate should start automatically by computer boot Select Yes or No and click Next An optional question asks if the Inte...

Страница 23: ...further instructions Click Install The program will be installed GUI only Choose this option if you wish to install only the GUI Select GUI only and click Next The GUI is installed in the following d...

Страница 24: ...ation Following any installation type you selected a window will list the performed installation steps Click Next You will see the following window If you want to start the GUI directly Activate the o...

Страница 25: ...Installation 24 AntiVir WebGate Avira GmbH...

Страница 26: ...etwork setting z In Monitoring FTP Traffic Page 30 is a description of integrating WebGate as FTP proxy z Integration over ICAP Interface Page 32 presents the integration of WebGate over ICAP interfac...

Страница 27: ...b AntiVir configantivir see Configuration Script Page 43 GUI avwebgate conf can be easily configured using the Configuration options in the graphical user interface GUI see Configuring AntiVir WebGate...

Страница 28: ...om the Client s point of view WebGate is functioning as a proxy server Make the following settings in avwebgate conf example HTTPPort 8080 Configure the browser according to the Clients For Proxy Serv...

Страница 29: ...es through the proxy server to the Internet and scans the answers from the Internet which are received through the proxy server The access to infected files from a Website is blocked and only not infe...

Страница 30: ...make any changes on the Clients It is also possible to install WebGate on a computer other than the proxy server The settings must be done accordingly In this network configuration a Client could also...

Страница 31: ...WebGate is installed on the proxy server machine Make sure that WebGate and the proxy server do not respond on the same server ports such as is the case in the above example WhenaClientasksfordata whi...

Страница 32: ...r name foo and the password bar ftp 192 168 0 1 2121 Connected to 192 168 0 1 220 AntiVir WebGate FTP proxy Login with user name host port Name 192 168 0 1 user foo 10 0 0 1 331 Password required for...

Страница 33: ...WebGate can still scan and block incoming RESPMOD and outgoing REQMOD files In avwebgate conf you must set the port through which WebGate will communicate with the ICAP Client ICAPPort 1344 Scanning...

Страница 34: ...returned to the ICAP Client and from there it is sent to the destination server If the request is blocked i e in case of a virus detection WebGate generates an HTML page based on the corresponding HTM...

Страница 35: ...Client or proxy computers There are various setups needed according to the configuration see Monitoring HTTP Traffic Page 26 The default is HTTPPort host_ip_or_name 8080 We recommend not to allow acce...

Страница 36: ...ill be separated by a comma or a whitespace AllowedHTTPConnectPorts 443 563 Max Connections Maximum number of connections allowed The maximum number of simultaneous connections allowed to run through...

Страница 37: ...r proxy HTTPProxyPort 8080 HTTPProxyUsername username HTTPProxyPassword password FTPProxy Settings for FTP proxy server If WebGate serves as FTP proxy see FTPPort option you can set a parent proxy for...

Страница 38: ...ttings for ArchiveMaxSize ArchiveMaxRecursion and ArchiveMaxRatio BlockSuspiciousArchive 0 Block Encrypted Archive Blocking password protected archives If this option is activated WebGate blocks passw...

Страница 39: ...e EmailTo root localhost AddX ForwardedFor Header Header analysis In case of a proxy chain network a downstream proxy server can make no analysis based on the Client s IP address because it sees all r...

Страница 40: ...ts 21 80 1025 65535 If you do not specify any ports the access is not restricted If you specify at least one port the access is permitted only on the entered ports Any other port has no access AclConf...

Страница 41: ...csMacro yes Heuristics Level Win32 Heuristics Sets the detection level of Win32 Heuristics available values are 0 off 1 low 2 medium and 3 high Default HeuristicsLevel 2 GUISupport Support over graphi...

Страница 42: ...ult setting You must enter the full path to the logfile in order to use this option LogTo var log avupdater log AutoUpdate Update scheduler The security software can check regularly for updates online...

Страница 43: ...is usually not necessary For security reasons both settings are by default deactivated Updater Keeps Backups The Internet Updater replaces installed files with newer versions when updates are availabl...

Страница 44: ...le the current ones are shown as default If you want to keep one of the current settings Press Enter If you want to change a setting Type the new value and confirm with Enter In the end a summary of t...

Страница 45: ...re at any time There are two possible methods to configure automatic AntiVir updates 1 You can use the Internet Updater which was delivered together with your AntiVir program and is easy to configure...

Страница 46: ...h Enter all remaining settings The Internet connection is now configured If this machine is sitting behind an HTTP proxy server you will need to config ure AntiVir with the appropriate proxy settings...

Страница 47: ...r manually Type usr lib AntiVir avupdater stop If you want to check the current status of the Internet Updater Type usr lib AntiVir avupdater status Configuring Automatic Updates in avupdater conf Upd...

Страница 48: ...n configantivir usr lib AntiVir configantivir First it asks you how often you need AntiVir to check for updates Type n if you do not want automatic updates AntiVir is equipped with an Internet Update...

Страница 49: ...more configuration possibilities than with the Internet Updater Example Enter the following cron job in etc crontab 45 2 root usr lib AntiVir antivir update q This command activates updates every 2 ho...

Страница 50: ...PGP key into your key ring gpg import antivir gpg Display the fingerprint of the key to check if it really is the AntiVir PGP key gpg fingerprint build avira com The 40 character fingerprint is displa...

Страница 51: ...vailable templates HTML Templates Template Meaning alert html Displayed when an alert is found by AvWebGate blocked html Displayed when AvWebGate has blocked a suspicious file using various block sett...

Страница 52: ...h a Test Virus Start WebGate usr lib AntiVir avwebgate start Type the following URL in your Web browser http www eicar org Read the information about the test virus eicar com Download the test virus o...

Страница 53: ...Configuration 52 AntiVir WebGate Avira GmbH...

Страница 54: ...d stop procedure of WebGate from the console z In Procedures when Detecting Viruses or Unwanted Programs Page 54 you can learn what you should do in case of an infection in your network 5 1 Starting a...

Страница 55: ...ou should however follow these guidelines Try to detect the way the infection sneaked on your system Perform targeted scanning on the data storage that might be infected Inform your team superiors or...

Страница 56: ...ation Type as root usr sbin usermod G group1 group2 group3 antivir username group1 group3 are the groups to which the user belongs username is the name of the user To set the groups for a user Type us...

Страница 57: ...st be installed in usr lib AntiVir z You must have a COMMERCIAL license for AntiVir WebGate antivir version z The parameter GuiSupport must be set in avwebgate conf z The user must belong to the antiv...

Страница 58: ...yellow text WebGate will be restarted More WebGates In case there are more WebGates in the network different situations can be displayed in the following format example 1 2 1 1 Meaning z 1 WebGate is...

Страница 59: ...s not stopped WebGate z Realtime view to display the graphical Realtime view z Logfile to switch to Logfile table window z Configuration to open the Configuration window z Load configuration to load a...

Страница 60: ...figuration see Basic WebGate Settings Page 63 The y axis changes automatically according to the current value levels Table with description The text description is divided in five columns z Computer s...

Страница 61: ...ayed log levels and the log level used by WebGate Four buttons appear on the bottom of the window Settings Rows Load new and More Settings Press Settings An additional area appears in the Logfile wind...

Страница 62: ...WebGate Start Select the menu option WebGate Start WebGate Stop Select the menu option WebGate Stop WebGate Restart Select the menu option WebGate Restart WebGate Changing the Time Intervals Set the t...

Страница 63: ...n Files Page 34 AntiVir GUI also applies to other AntiVir products and in case you have more products installed on the same computer it displays the options according to the selected product When work...

Страница 64: ...directory stores for example the files during scanning HTTP Port This entry sets the port on which WebGate communicates for HTTP connections with the Client computer or the proxy server It may need va...

Страница 65: ...possibilities The entries are given in seconds z If the Client is a browser WebGate sends an HTML progress page which is updated at regular intervals The time interval is set with Refresh Interval z...

Страница 66: ...Page 38 Activate Heuristics If you activate heuristics WebGate also traces unknown viruses You can set the detection level for Win32 Heuristics Quarantine Directory Enter the directory you want to st...

Страница 67: ...P connections z Server Proxy server s hostname or IP The parameters are HTTPProxyServer and FTPProxyServer in avwebgate conf z Port Port for proxy server communication with WebGate The parameters are...

Страница 68: ...smaller than the maximum size in Bytes The null value means no limit Default is 1 GB It corresponds to ArchiveMaxSize in avwebgate conf Maximum recursion When scanning recursive archives the level of...

Страница 69: ...kSuspiciousArchive in avwebgate conf Block encrypted archives If activated this option blocks password protected archives It corresponds to BlockEncryptedArchive in avwebgate conf Block partial archiv...

Страница 70: ...NG z 5 NOTICE z 6 INFO z 7 DEBUG For example LogLevel 4 means that the logfile contains all EMERGENCY ALERT CRITICAL ERROR and WARNING notifications NOTICE INFO and DEBUG messages will not be recorded...

Страница 71: ...tiVir antivir gui Define the basic settings in Basic WebGate Settings Page 63 Define the extended settings If you are not sure about possible values for example the maximum number of connections allow...

Страница 72: ...dater tab The Updater main window displays information about the Operating System and the Versions of the product engine PackLib and VDF A scroll text area describes the current Updater activity You c...

Страница 73: ...Configuration to open the Configuration window Start Update to update WebGate Updater Logfile Window Click on the Logfile button OR Select the menu option Updater Logfile The Logfile window appears Lo...

Страница 74: ...the number of Lines given 6 5 Configuring AntiVir Updater Using the GUI You can make the configuration settings for AntiVir Updater directly in the GUI AntiVir GUI also applies to other AntiVir produc...

Страница 75: ...pdater conf are AutoUpdateEvery2Hours AutoUpdateDaily AutoUpdateTime Updater Proxy Settings HTTP Proxy Here you must set the HTTP connection for updates z Server update proxy server s hostname or IP z...

Страница 76: ...yslog daemon You could specify an additional logfile by entering the full path For example var log avupdater log It corresponds to LogTo in avupdater conf Email AntiVir Updater is able to send emails...

Страница 77: ...Graphical User Interface GUI 76 AntiVir WebGate Avira GmbH...

Страница 78: ...chased AntiVir program Another optional service is the AntiVir Premium Support which offers you additionally to the scope of the AntiVir Classic Supports the possibility to reach competent partners at...

Страница 79: ...e 78 AntiVir WebGate Avira GmbH 7 3 Contact Address Avira GmbH Lindauer Strasse 21 D 88069 Tettnang Germany Internet You can find further information about us and our products by visiting http www avi...

Страница 80: ...nnection charging you at higher rates This can lead to huge phone bills AntiVir detects Dialers Engine The scanning module of AntiVir software Heuristic The systematic process of solving a problem usi...

Страница 81: ...ric Multi Processing Unix SMP Unix version for computers with parallel processors SMTP Simple Mail Transfer Protocol protocol for email transport on the Internet syslog daemon A daemon used by program...

Страница 82: ...g and during installation If there are other users connected to your computer you should set the following rules for protection against viruses Use a test computer for controlling downloads of new sof...

Страница 83: ...rors excepted Content suject to change Issued Q4 2007 AntiVir is a registered trademark of the Avira GmbH All other brand and product names are trademarks or registered trademarks of their respective...

Отзывы: