
How to Configure McAfee VirusScan Enterprise for the Oracle ZFS Storage Appliance
16
The Oracle ZFS Storage Appliance also can be checked for reported infected files using
the Logs option in the Virus Scan Services information window. Select the Log of vscan
option to verify that the test files copied onto the NFS share have been reported here too.
Figure 14. Oracle ZFS Storage Appliance virus scan logs
Configuration Best Practices
Note the following file handling cases and consider the recommended settings for
managing them.
Handling Archive Type Files
Methods for handling mime and zip archive type files require special consideration, as
virus threats can hide in compressed files that are part of the archive file. Viruses can only
be detected by unpacking the archives and scanning the individual files in the archives for
the viruses' presence.
You can wait for a user to unpack an archive file and let the virus scanner pick up the
threat at that time. Otherwise, you can set the virus scanner to unpack the file as soon as
it is added to a file system, but this prevents the zip file from being further copied in an
organization's infrastructure. This approach imposes an extra load on the virus scanner
and can only handle archives that are not password protected or encrypted. Thus, you
should note that enabling scanning of zip files contents is not a 100% reliable method for
detecting a virus threat in files within an archive file.
McAfee VSE can manage both archive scan approaches; when an immediate archive
scan is required, it can be configured. To make sure zip-type archive files and MIME
Decoded files are also processed by the AV Scanner, include them in the file types to
scan.
Use the ICAP AV Scanner Scan Items tab to specify the Decode Mime encoded files
and Scan inside archives options.
Kommentare zu diesen Handbüchern