LinuxQuestions.org
Visit Jeremy's Blog.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 04-09-2008, 08:33 PM   #1
utahnix
Member
 
Registered: Dec 2006
Location: Utah, USA
Distribution: openSUSE
Posts: 72

Rep: Reputation: 15
How do I virus scan web content that passes through NAT box?


Lately I've been looking at scanning web content that passes through my Linux gateway box (SNAT). I'm currently running openSUSE 10.3, using iptables to do the SNAT. I really love iptables and what it is able to do.

But virus scanning... I was thinking about setting up Squid, and then using Virulator to scan proxied data through something like ClamAV (i.e. virulator bridges the gap between Squid (proxy) and the Virus scanner (ClamAV)).

I've looked at some solutions like Untangle or Endian, and considered them, but don't like them. They feel really awkward and clumsy to me (especially Untangle). The other thing is, I am very familiar with SUSE distros, and I know SUSE runs on my hardware. So I'm sorta reluctant to switch.

But one thing that Endian can supposedly do is scan traffic on port 80 without actually setting up a proxy on the gateway machine. So it simply scans content passing through the machine that goes over that port.

So I guess what I'm asking is there something like this (ability to transparently scan web traffic that passes through this box) that can run on a regular distro like openSUSE? If proxy is necessary, is there something better out there than a Squid+Virulator solution?
 
Old 04-09-2008, 08:38 PM   #2
billymayday
LQ Guru
 
Registered: Mar 2006
Location: Sydney, Australia
Distribution: Fedora, CentOS, OpenSuse, Slack, Gentoo, Debian, Arch, PCBSD
Posts: 6,678

Rep: Reputation: 122Reputation: 122
Why can't you run squid as a transparent proxy and use a squid based solution?
 
Old 04-09-2008, 09:11 PM   #3
utahnix
Member
 
Registered: Dec 2006
Location: Utah, USA
Distribution: openSUSE
Posts: 72

Original Poster
Rep: Reputation: 15
I didn't know Squid could run as a transparent proxy...

To be honest, I've never run Squid. I know it's considered a very high caliber product, and I've been seriously looking at it. I'm simply trying to find the most effective solution that isn't going to be highly difficult to get working that'll be the most seamless solution to the users involved.

But doesn't Squid need a "middle man" to a virus scanner, much like Amavis is to Postfix and ClamAV?
 
Old 04-09-2008, 09:17 PM   #4
billymayday
LQ Guru
 
Registered: Mar 2006
Location: Sydney, Australia
Distribution: Fedora, CentOS, OpenSuse, Slack, Gentoo, Debian, Arch, PCBSD
Posts: 6,678

Rep: Reputation: 122Reputation: 122
I think do - there are products like squid-clamav around. Do a bit of googling
 
Old 04-10-2008, 05:14 PM   #5
win32sux
LQ Guru
 
Registered: Jul 2003
Location: Los Angeles
Distribution: Ubuntu
Posts: 9,870

Rep: Reputation: 380Reputation: 380Reputation: 380Reputation: 380
The 2.9.x.y branch of DansGuardian has built-in virus scanning support.

Also maybe have a look at HAVP, which can be used standalone.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Good Linux Virus Scan !!! chuck77 Linux - General 4 09-02-2008 02:54 AM
ClamV Virus scan on Linux shankarLe Linux - Software 3 08-22-2007 11:55 PM
Updating avamisd-new VIrus Scan gizza23 Linux - Server 3 11-30-2006 08:44 AM
Is there a virus scan software in linux? Itachi Mandriva 12 02-08-2005 07:59 PM
Ran a virus scan, please look at.. webwolf70 Linux - Security 3 01-29-2005 11:54 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 05:32 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration