User guide
Using VStream Antivirus
508 Check Point Safe@Office User Guide
If a virus if found in
this protocol...
VStream Antivirus does this...
The protocol is detected
on this port...
IMAP
• Terminates the
connection
• Replaces the virus-
infected email with a
message notifying the
user that a virus was
found
The standard TCP port 143
SMTP
• Rejects the virus-infected
email with error code 554
• Sends a "Virus detected"
message to the sender
The standard TCP port 25
FTP
• Terminates the data
connection
• Sends a "Virus detected"
message to the FTP
client
The standard TCP port 21
TCP and UDP
• Terminates the
connection
Generic TCP and UDP ports,
other than those listed above
Note: In protocols that are not listed in this table, VStream Antivirus uses a "best
effort" approach to detect viruses. In such cases, detection of viruses is not
guaranteed and depends on the specific encoding used by the protocol.
Default Antivirus Policy
The VStream Antivirus default policy includes the following rules:
• All SMTP connections are scanned, regardless of the connection's direction.
• All POP3 connections are scanned, regardless of the connection's direction.
• All IMAP connections are scanned, regardless of the connection's direction.
You can easily override the default antivirus policy, by creating user-defined rules. For
further information, see Configuring the VStream Antivirus Policy on page 511.