Open Frames Download Complete PDF Send Feedback Print This Page

Previous

Next

Getting Started with Anti-Virus

In This Section:

Enabling the Anti-Virus Software Blade

Creating an Anti-Virus Policy

Blocking Viruses

Enabling the Anti-Virus Software Blade

Enable the Anti-Virus Software Blade on a Security Gateway.

To enable the Anti-Virus Software Blade:

  1. In SmartDashboard, right-click the gateway object and select Edit.

    The Gateway Properties window opens.

  2. In Network Security tab, select Anti-Virus.

    The Anti-Bot and Anti-Virus First Time Activation window opens.

  3. Select one of the activation mode options:
    • According to the Anti-Bot and Anti-Virus policy - Enable the Anti-Virus Software Blade and use the Anti-Virus settings of the Threat Prevention profile in the Threat Prevention policy.
    • Detect only - Packets are allowed, but the traffic is logged according to the settings in the Threat Prevention Rule Base.
  4. Click OK
  5. Install the Threat Prevention policy.

Creating an Anti-Virus Policy

Create and manage the policy for the Anti-Virus Software Blade in the Threat Prevention tab of SmartDashboard. The policy shows the profiles set for network objects or locations defined as a protected scope.

  • The Overview pane shows a high-level summary of your Anti-Virus activity and traffic.
  • The Policy pane shows the rules and exceptions for the Anti-Virus policy. Click the Add Rule button to get started.
  • To learn about malware and protections, look through the Threat Wiki.

You can use Anti-Virus rules to disable a specified malware protection.

After you create and configure the rules, install the policy on the specified Security Gateways.

Blocking Viruses

Scenario: I want to block viruses and malware in my organization. How can I do this?

To block viruses in your organization:

  1. In the Gateway Properties page, select the Anti-Virus Software Blade.

    The First Time Activation window opens.

  2. Select According to the Anti-Bot and Anti-Virus policy and click OK.
  3. Select Threat Prevention > Policy.
  4. Click Add Rule.

    A new rule is added to the Threat Prevention policy. The Software Blade applies the first rule that matches the traffic.

  5. Make a rule that includes these components:
    • Name - Give the rule a name, such as Block Virus Activity.
    • Protected Scope - Add the network objects you want to protect. In this example, the Any network object is used.
    • Action - Select the Profile with the protection settings you want. The default profile is Recommended_Profile.
    • Track - Select the type of log to get when malware is detected. In this example, keep Log and also select Packet Capture, to capture the packets of malicious activity. In SmartView Tracker, you can see the captured packets.
    • Install On - Keep it as All, or select gateways to install the rule on.
  6. Install the Threat Prevention policy.
 
Top of Page ©2015 Check Point Software Technologies Ltd. All rights reserved. Download PDF Send Feedback Print