Installation manual

3
1. Introduction
Thank you for using ESET Gateway Security - the premier security system for Linux, BSD and Solaris. ESET's state-of-the-art
scanning engine has unsurpassed scanning speed and detection rates combined with a very small footprint that makes it the
ideal choice for any server on Linux, BSD and Solaris.
1.1 Main functionality
Hypertext Transfer Protocol filter (HTTP)
The HTTP filter module is an HTTP 1.1 compliant special proxy server used to scan communication between HTTP clients and
HTTP servers for viruses. The module receives HTTP messages from an HTTP client (a web browser application or other proxy
cache) and forwards them to the HTTP server (a web server application) and vice versa. The body of the message (if available)
will be scanned for viruses by the esets_http module.
The esets_http is able to act as both a transparent and a non-transparent proxy server depending on the integration of the
module into the environment.
File Transfer Protocol filter (FTP)
The FTP filter module is a special transparent proxy server that scans communication between an ftp client and an ftp server for
viruses. The FTP gateway module is used to scan both incoming and outgoing data transfers. Depending on the scanning results,
a transferred object will be cleaned, deleted or blocked.
SafeSquid filter
The SSFI module is a plugin accessing all objects processed by the SafeSquid Proxy cache. Once an object is accessed by the
plugin, it will be scanned for infiltrations by the ESETS daemon. In the case of a positive detection, SSFI blocks the appropriate
source and sends a predefined template page instead. The esets_ssfi.so module is supported by SafeSquid Advanced version
4.0.4.2 and higher.
Internet Content Adaptation Protocol filter (ICAP)
The ICAP filter module is an ICAP 1.0 compliant special server that scans ICAP encapsulated HTTP messages from ICAP clients for
viruses.
1.2 Key features of the system
Advanced engine algorithms
The ESET antivirus scanning engine algorithms provide the highest detection rate and the fastest scanning times.
Multi-processing
ESET Gateway Security is developed to run on single- as well as multi-processor units.
Advanced Heuristics
ESET Gateway Security includes unique advanced heuristics for Win32 worms, backdoor infections and other forms of malware.
Built-In features
Built-in archivers unpack archived objects without requiring any external programs.
Speed and efficiency
To increase the speed and efficiency of the system, ESET Gateway Security's architecture is based on the running daemon
(resident program) where all scanning requests are sent.
Enhanced security
All executive daemons (except esets_dac) run under a non-privileged user account to enhance security.
Selective configuration
The system supports selective configuration based on the user or client/server.
Multiple logging levels
Multiple logging levels can be configured to get information about system activity and infiltrations.