SonicWALL TZ 180 manual Disabling the SonicWALL GAV/IPS Engine, Protocol Handling

Page 9

SonicWALL Gateway Anti-Virus

Stream Concurrency Limitations by SonicWALL Security Appliance

Because SonicWALL GAV does not have to perform reassembly, there are no file-size limitations imposed by the scanning engine. Base64 decoding, ZIP, LHZ, and GZIP (LZ77) decompression are also performed on a single-pass, per-packet basis. Stream-concurrency are platform dependent as follows:

 

 

GAV-Enabled

Concurrent

 

 

 

Connections

 

 

GAV-Disabled

Cache Size

Compressed

 

 

Connections

(Concurrent

File Downloads

 

Platform

Cache Size

File Downloads)

with GAV

GAV Signatures

 

 

 

 

 

TZ 150

2,048

2,048

100

4,500

Series

 

 

 

 

 

 

 

 

 

TZ 170

6,144

6,144

100

4,500

Series

 

 

 

 

 

 

 

 

 

PRO 1260

6,144

6,144

100

4,500

 

 

 

 

 

PRO 2040

32,768

16,384

300

25,000

 

 

 

 

 

PRO 3060

131,072

65,536

1,000

25,000

 

 

 

 

 

PRO 4060

524,288

131,072

1,500

25,000

 

 

 

 

 

PRO 5060

750,000

393,216

3,000

25,000

 

 

 

 

 

Disabling the SonicWALL GAV/IPS Engine

In the unlikely event that SonicWALL Gateway Anti-Virus/Intrusion Prevention Service is not enabled on your SonicWALL security appliance, the SonicWALL GAV/IPS engine itself can be disabled, and the resources can be reallocated to the SPI connection cache.

To disable the SonicWALL GAV/IPS engine, perform the following steps:

Step 1 Select the Firewall > Advanced page.

Step 2 Select the Disable Gateway AV and IPS Engine (increases maximum SPI connections) checkbox. This presents an alert informing you that the SonicWALL security appliance must be rebooted for the change to take effect.

Step 3 Restart your SonicWALL security appliance.

Protocol Handling

SonicWALL GAV functionality supports the following protocols: HTTP, SMTP, IMAP, POP3, FTP and the scanning of generic TCP streams for viruses.

If malicious traffic is detected, appropriate actions are taken based on the protocol. For generic TCP streams, the traffic is dropped and the connection is reset. If so configured, an encrypted and hashed message explaining the action is sent to the user's Global Security Client (requires version

2.0or higher) and to the user's 'Security Action Notification Applet', and displayed to the user if either application is active. Application level awareness of the type of protocol that was transporting the violation allows for very specific actions to be taken to gracefully handle the rejection of the payload:

SonicWALL TZ 180 TotalSecure

9

Image 9
Contents What is TotalSecure? IntroductionDocument Scope Benefits of TotalSecure Every SonicWALL TotalSecure solution includes the followingGAV Overview SonicWALL Gateway Anti-VirusHow Does GAV Work? BenefitsSonicWALL Gateway Anti-Virus/Intrusion Prevention Features SonicWALL GAV Multi-Layered Approach Internal Network Protection Remote Site ProtectionHttp File Downloads Server Protection SonicWALL GAV ArchitectureProtocol Handling Disabling the SonicWALL GAV/IPS EngineSmtp SonicWALL Intrusion Prevention Service IPS OverviewHow Does IPS Work? What is a Zone? SonicWALL Anti-Spyware Security Service SonicWALL Anti-SpywareSpyware Threat SonicWALL Anti-Spyware SonicWALL Content Filtering Service Premium CFS OverviewHow Does CFS Premium Work? SonicWALL Deep Packet Inspection DPI OverviewHow Does DPI Work? Deep Packet Inspection Flow Diagram SonicWALL Security Dashboard Security Dashboard Overview SonicWALL Security Dashboard How Does the Security Dashboard Work? What is Security Dashboard?Registering Your Appliance on MySonicWALL Registering Your Appliance on MySonicWALL Registering Your SonicWALL Security Appliance TotalSecure Configuration Task ListSetting Up SonicWALL GAV Protection Enabling SonicWALL GAVApplying SonicWALL GAV Protection on Interfaces Edit Zone Applying SonicWALL GAV Protection on Zones SonicOS EnhancedViewing SonicWALL GAV Status Information Updating SonicWALL GAV Signatures Specifying Protocol FilteringEnabling Inbound Inspection Enabling Outbound Smtp Inspection Configuring Client Alerts and an Exclusion ListConfiguring Client Alerts Configuring a SonicWALL GAV Exclusion ListRestricting File Transfers Displaying Signatures Viewing SonicWALL GAV SignaturesEnabling SonicWALL IPS Navigating the Gateway Anti-Virus Signatures TableBrute-force Baseline Setup Enable IPS LoggingSetting Up SonicWALL Anti-Spyware Protection Enabling SonicWALL Anti-Spyware Setting Up CFS Premium GlossarySpecifying Spyware Danger Level Protection Glossary Related Documentation Solution Document Version History Version Number Date Related Documentation SonicWALL TZ 180 TotalSecure
Related manuals
Manual 34 pages 40.02 Kb Manual 38 pages 55.88 Kb