User's Manual Part 2

Overview
Chapter 10: Using VStream Antivirus 265
Chapter 10
This chapter explains how to use the VStream Antivirus engine to block security
threats before they reach your network.
This chapter includes the following topics:
Overview..................................................................................................265
Enabling/Disabling VStream Antivirus....................................................267
Viewing VStream Signature Database Information .................................268
Configuring VStream Antivirus ...............................................................269
Updating VStream Antivirus....................................................................281
Overview
The Safe@Office appliance includes VStream Antivirus, an embedded stream-
based antivirus engine based on Check Point Stateful Inspection and Application
Intelligence technologies, that performs virus scanning at the kernel level.
VStream Antivirus scans files for malicious content on the fly, without
downloading the files into intermediate storage. This means minimal added latency
and support for unlimited file sizes; and since VStream Antivirus stores only
minimal state information per connection, it can scan thousands of connections
concurrently. In order to scan archive files on the fly, VStream Antivirus performs
real-time decompression and scanning of ZIP, TAR, and GZ archive files, with
support for nested archive files.
When VStream Antivirus detects malicious content, the action it takes depends on
the protocol in which the virus was found. See the table below. In each case,
VStream Antivirus blocks the file and writes a log to the Event Log.
Using VStream Antivirus