•
ICAP AV scanning—This method forwards traffic to an Internet Content Adaptation
Protocol (ICAP) server for examination. To forward traffic to an ICAP server, create an
ICAP server object, create an ICAP profile, and then specify that profile in a policy.
Configuring External AV Profiles
External AV profiles define the external Trend Micro AV scanner server that a security
device uses to detect viruses in specific protocols. This feature describes the external
scanner supported by ScreenOS 5.0 — 5.3. For ScreenOS 5.4 and later, use an ICAP AV
profile as described in “Configuring ICAP AV Profiles” on page 372
You must configure an AV profile when using external AV for virus protection on your
security device. After you have configured an AV profile, you can use the profile within a
firewall rule.
NOTE:
You can configure additional settings for external antivirus protection on the
security device itself. For details, refer to Network and Security Manager Configuring
ScreenOS and IDP Devices Guide.
External AV profiles contain the following information:
•
Server Name and Port—You must specify the IP address and port number of the external
antivirus server that contains your virus definitions.
•
Protocols and Timeouts—You must specify the protocols (HTTP and SMTP) that the
external AV server scans for viruses. The default protocol timeout is 180 seconds, but
you can edit this default to meet your networking requirements.
You must use the AV profile in a firewall rule and install that rule on a security device
before the external scanner can begin inspecting traffic for viruses. For information about
using AV profiles in rules.
In this example, you configure an AV profile that sends all HTTP traffic to an external
antivirus server at 1.2.2.20 for virus checking. Because you anticipate heavy HTTP loads
on the network, you increase the timeout from 180 seconds (the default setting) to 300
seconds.
1.
In the main navigation tree, select
Object Manager
>
UTM
>
ScreenOS
>
AV
Objects
>
External.
2.
In the main display area, click the Add icon. The New AntiVirus Profile dialog box
appears.
3.
Configure the following:
•
For Name, scanner1_HTTP
•
For Server Name, enter 1.2.2.20.
•
For Server Port, leave the default port number of 3300.
4.
Select HTTP, then configure the timeout as 300 seconds.
5.
Click
OK
to save the new profile.
369
Copyright © 2010, Juniper Networks, Inc.
Chapter 8: Configuring Objects
Содержание NETWORK AND SECURITY MANAGER 2010.3
Страница 6: ...Copyright 2010 Juniper Networks Inc vi...
Страница 36: ...Copyright 2010 Juniper Networks Inc xxxvi Network and Security Manager Administration Guide...
Страница 52: ...Copyright 2010 Juniper Networks Inc 2 Network and Security Manager Administration Guide...
Страница 90: ...Copyright 2010 Juniper Networks Inc 40 Network and Security Manager Administration Guide...
Страница 144: ...Copyright 2010 Juniper Networks Inc 94 Network and Security Manager Administration Guide...
Страница 146: ...Copyright 2010 Juniper Networks Inc 96 Network and Security Manager Administration Guide...
Страница 234: ...Copyright 2010 Juniper Networks Inc 184 Network and Security Manager Administration Guide...
Страница 310: ...Copyright 2010 Juniper Networks Inc 260 Network and Security Manager Administration Guide...
Страница 364: ...Copyright 2010 Juniper Networks Inc 314 Network and Security Manager Administration Guide...
Страница 366: ...Copyright 2010 Juniper Networks Inc 316 Network and Security Manager Administration Guide...
Страница 478: ...Copyright 2010 Juniper Networks Inc 428 Network and Security Manager Administration Guide...
Страница 576: ...Copyright 2010 Juniper Networks Inc 526 Network and Security Manager Administration Guide...
Страница 580: ...Copyright 2010 Juniper Networks Inc 530 Network and Security Manager Administration Guide...
Страница 592: ...Copyright 2010 Juniper Networks Inc 542 Network and Security Manager Administration Guide...
Страница 684: ...Copyright 2010 Juniper Networks Inc 634 Network and Security Manager Administration Guide...
Страница 690: ...Copyright 2010 Juniper Networks Inc 640 Network and Security Manager Administration Guide...
Страница 696: ...Copyright 2010 Juniper Networks Inc 646 Network and Security Manager Administration Guide...
Страница 698: ...Copyright 2010 Juniper Networks Inc 648 Network and Security Manager Administration Guide...
Страница 748: ...Copyright 2010 Juniper Networks Inc 698 Network and Security Manager Administration Guide...
Страница 778: ...Copyright 2010 Juniper Networks Inc 728 Network and Security Manager Administration Guide...
Страница 870: ...Copyright 2010 Juniper Networks Inc 820 Network and Security Manager Administration Guide...
Страница 872: ...Copyright 2010 Juniper Networks Inc 822 Network and Security Manager Administration Guide...
Страница 898: ...Copyright 2010 Juniper Networks Inc 848 Network and Security Manager Administration Guide...
Страница 908: ...Copyright 2010 Juniper Networks Inc 858 Network and Security Manager Administration Guide...
Страница 910: ...Copyright 2010 Juniper Networks Inc 860 Network and Security Manager Administration Guide...
Страница 995: ...PART 6 Index Index on page 947 945 Copyright 2010 Juniper Networks Inc...
Страница 996: ...Copyright 2010 Juniper Networks Inc 946 Network and Security Manager Administration Guide...