Security Services
Anti-Virus
Cisco ISA500 Series Integrated Security Appliance Administrator Guide
221
7
•
Select which zone to scan for virus:
Specify the zones to scan the viruses
for the incoming traffic from the selected zones:
-
WAN zone:
Choose this option to scan the viruses only for the traffic from
WAN zone to all other zones.
-
WAN + VPN zone:
Choose this option to scan the viruses for the traffic
from both WAN and VPN zones to all other zones.
-
All zones:
Choose this option to scan the viruses for the incoming traffic
from
all zones. This is the default setting.
STEP 3
Specify the following settings for the protocols that you want to scan for viruses:
•
Enable:
Check the box in this column to scan for the viruses for the protocol.
•
Log:
Check the box in this column to log the event when viruses are
detected.
To log the Anti-Virus events, you first need to check the
Log
box for the
protocols, and then go to the
Device Management -> Loggings
pages to
configure the log settings and log facilities:
-
To save the Anti-Virus logs in the lcoal syslog daemon, you need to enable
the Log feature, set the log buffer size and the severity for local log, and
then check the
Local Log
box for the
Anti-Virus
log facility.
-
To save the Anti-Virus logs to the remote syslog server if you have a
remote syslog server support, you need to enable the Log feature,
specify the Remote Log settings, and check the
Remote Log
box for the
Anti-Virus
log facility.
For more information about how to configure the log settings and log
facilities, and how to view the logs, see
•
Action:
Specify the preventive action for each protocol when viruses are
detected.
-
None:
No action is required when viruses are detected.
-
Alert:
Sends an alert email to the specified email account when viruses
are detected for the SMTP or POP3 protocol, or sends an alert message
to the user when using the HTTP protocol to download the files
containing viruses.
-
Drop Connection:
Drops the connection when viruses are detected.
-
Destruct File:
Destructs the file when viruses are detected.