Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

anti-virus scanning failures

Running Sophos XG 16.5 MR6 with what I believe includes AV, IPS and such, but I was running some basic security tests and it looks like all the virus scanning and botnet protection is not working at all.

This fails ALL the tests: http://www.cyren.com/security-test

Fails ALL but the first one: http://metal.fortiguard.com/tests/

 

Web -> Protection

  • Scan Engine: Dual Engine
  • Malware scan mode: Batch
  • Malware that cannot be scanned: Block
  • Do not scan files larger than 75MB
  • Scan audio and video: Unchecked (caused issues with streaming)
  • Enable pharming protection: Unchecked (caused issues with iOS Snapchat app)

 

Are the above settings wrong or is it possible that I'm looking in the completely wrong section?  It doesn't feel like Sophos is actually doing anything UTM related to protect me.



This thread was automatically locked due to age.
Parents
  • Hi,

    I ran the tests against my XG 5.6-mr6.

    It failed 3 of the cyren tests, virus over ssl. botnet and anonymiser. Currently I don't scan https/tls due to a certificate issue. Botnet call home is a worry.

    It failed all the fortiguard tests because it blocked zip files which is a bit strange because I have scan zip files enabled (I think).

    The current version of XG is not capable of blocking everything, but just warns you. I am lead to believe that v17 will fix this issue.

    Some of your issues are possibly caused by your rule configuration and order of precedence.

    Please post what you think is your rule that should be blocking the test traffic.

     

    Ian

  • Hi,

    I tried tightening my rules to see if there is any improvement in the test results, for botnet, total failure all you can do is set the XG to warn you that the sites are objectionable, not satisfactory.

    Ian

  • I would like to add my results too:

    I use decrypt and scan, Avira as AV. Unscannable content is blocked (which it is  safer but manual exception needs to be managed).

    Here my Web Policy:

    For Fortiguard test, all will fail because unscannable content is enabled.

    Regards

Reply
  • I would like to add my results too:

    I use decrypt and scan, Avira as AV. Unscannable content is blocked (which it is  safer but manual exception needs to be managed).

    Here my Web Policy:

    For Fortiguard test, all will fail because unscannable content is enabled.

    Regards

Children