ZyXEL Communications ZyWALL 300 User Manual
Chapter 28 Anti-Virus
ZyWALL USG 300 User’s Guide
409
Protocols to Scan
Select which protocols of traffic to scan for viruses.
FTP applies to traffic using the TCP port number specified for FTP in the ALG
screen.
HTTP applies to traffic using TCP ports 80, 8080 and 3128.
SMTP applies to traffic using TCP port 25.
POP3 applies to traffic using TCP port 110.
IMAP4 applies to traffic using TCP port 143.
FTP applies to traffic using the TCP port number specified for FTP in the ALG
screen.
HTTP applies to traffic using TCP ports 80, 8080 and 3128.
SMTP applies to traffic using TCP port 25.
POP3 applies to traffic using TCP port 110.
IMAP4 applies to traffic using TCP port 143.
Actions When
Matched
Matched
Destroy infected
file
file
When you select this check box, if a virus pattern is matched, the ZyWALL
overwrites the infected portion of the file (and the rest of the file) with zeros. The
un-infected portion of the file before a virus pattern was matched goes through
unmodified.
overwrites the infected portion of the file (and the rest of the file) with zeros. The
un-infected portion of the file before a virus pattern was matched goes through
unmodified.
Send Windows
Message
Message
Select this check box to set the ZyWALL to send a message alert to files’ intended
user(s) using Microsoft Windows computers connected to the to interface.
user(s) using Microsoft Windows computers connected to the to interface.
Log
These are the log options:
no: Do not create a log when a packet matches a signature(s).
log: Create a log on the ZyWALL when a packet matches a signature(s).
log alert: An alert is an e-mailed log for more serious events that may need more
immediate attention. Select this option to have the ZyWALL send an alert when a
packet matches a signature(s).
no: Do not create a log when a packet matches a signature(s).
log: Create a log on the ZyWALL when a packet matches a signature(s).
log alert: An alert is an e-mailed log for more serious events that may need more
immediate attention. Select this option to have the ZyWALL send an alert when a
packet matches a signature(s).
White List / Black
List Checking
List Checking
Bypass white list
checking
checking
Select this check box to not check files against the white list. This disables the
white list for traffic that matches this anti-virus rule.
white list for traffic that matches this anti-virus rule.
Bypass black list
checking
checking
Select this check box to not check files against the black list. This disables the
black list for traffic that matches this anti-virus rule.
black list for traffic that matches this anti-virus rule.
File
decompression
decompression
Enable file
decompression
(ZIP and RAR)
decompression
(ZIP and RAR)
Select this check box to have the ZyWALL scan a ZIP file (the file does not have to
have a “zip” or “rar” file extension). The ZyWALL first decompresses the ZIP file
and then scans the contents for viruses.
have a “zip” or “rar” file extension). The ZyWALL first decompresses the ZIP file
and then scans the contents for viruses.
Note: The ZyWALL decompresses a ZIP file once. The ZyWALL
does NOT decompress any ZIP file(s) within a ZIP file.
Table 122 Anti-X > Anti-Virus > General > Edit (continued)
LABEL
DESCRIPTION