Security Assurance Appliance  Virus Blocker

Block Viruses at the Network Gateway

Stop virus outbreaks before they reach users desktops. With an intuitive GUI and the ability to scan multiple protocols, Untangle makes it easier for administrators to:

  • Protect users from virus threats over web (http), email (SMTP, POP & IMAP) and file transfer (FTP) protocols
  • Scan archives and compressed files like Zip, RAR, Tar and many others
  • Ensure that signatures are always current with automatic updates

Viruses can disrupt business, destroy data, and spread to your customers—a scenario that no business owner ever wants to face. You can now protect your entire network from virus threats with our purpose-built antivirus application. Whether it’s a virus, worms, Trojans or malware, our Virus Blocker keeps emails, webmail, downloads and file transfers safe with the latest advances in antivirus technology, and works within a variety of different protocols.

Your business gets full, comprehensive virus protection, updated regularly, so you’ll always have the most current protection available. Plus, you’ll also get the big picture view of your antivirus environment, including what viruses are being blocked.

Key Features:

  • Open source & free under the GNU General Public License (GPL)
  • Unlike desktop solutions, Untangle sits at the network gateway so there is only one application to keep up-to-date, and Untangle does that automatically
  • Protection on the most common email protocols SMTP, IMAP, and POP
  • Protection for webmail and file transfer via HTTP and FTP protocols, an increasingly common route for infection
  • Reports and event logs show you what viruses are being blocked on the network

Virus Blocking Technical Specifications

Virus Blocker and Kaspersky Virus Blocker protect your network against viruses. Viruses infect networks in many different ways, so our Virus Blocking applications scan numerous protocols for viral signatures including:

  • Email: SMTP, POP, IMAP
  • Web: HTTP
  • File Transfer: FTP

Virus Blocker is based on an open source virus scanner, ClamAV, while Kaspersky Virus Blocker leverages Kaspersky . Both Applications:

  • Detect viruses, worms, and trojan horses
  • Scan within archives and compressed files: Zip, RAR, Tar, Gzip, Bzip2, MS OLE2, MS Cabinet Files, MS CHM, and MS SZDD
  • Protect against archive bombs, files that are repeatedly compressed. Such files cause other virus scanners or programs to crash or hang by consuming all CPU resources. Intensive resource consumption can occur when other virus scanners scan numerous levels of files within files; however, Untangle Virus Blocker products thwart this technique

What It Does

Transparently scans HTTP, FTP, SMTP, POP and IMAP traffic for viral signatures

How It Does It

Virus Blocker and Kaspersky Virus Blocker use on-the-fly decompression of archive files for scanning and can scan arbitrarily large files

Controls
  • Can be configured to scan incoming and/or outgoing by traffic type
  • In addition,
    • HTTP: configurable scanning by file extension or MIME type
    • SMTP: action on detection can be set to remove infection, block or pass message, with or without sender and/or receiver notification
    • POP and IMAP: action on detection can be set to remove infection or pass message (the nature of POP and IMAP protocols prevents messages from being blocked, but they can be scanned and cleansed)
    • FTP and HTTP: “download resume” can be disabled
  • Scan trickle rate can be configured to support very large files