LinuxQuestions.org

LinuxQuestions.org (/questions/)
-   Linux - Security (https://www.linuxquestions.org/questions/linux-security-4/)
-   -   Network Wide Anti-virus (https://www.linuxquestions.org/questions/linux-security-4/network-wide-anti-virus-267506/)

kegwell 12-17-2004 04:12 PM

Network Wide Anti-virus
 
I was hoping somebody could point me in the correct direction in regards to an open source network wide antivirus solution. I am not concerned with email as we already have virus security in place for that. I am more concerned with virus security for an entire network block. I was thinking of implenting some type of NAT so all traffic from this particular network will go through one machine. What would you recommend to monitor traffic on this machine? Would a client side AV solution be wiser? If so, anything that can be remotely administered?

--Thanks

Caeda 12-17-2004 05:58 PM

Are there windows pcs involved here somewhere? If not, why bother with AV?

win32sux 12-19-2004 08:13 AM

try clamav:

http://www.clamav.net/

there's lots of third-party software for it which lets you scan all traffic going through the gateway with it...

kegwell 12-20-2004 08:38 AM

Yes, 99% of the clients are windows based machines.

win32sux 12-20-2004 08:43 AM

Quote:

Originally posted by kegwell
Yes, 99% of the clients are windows based machines.
well, there you go... you can scan all the network traffic with clamav...

good luck...

kegwell 12-20-2004 08:47 AM

ClamAV appears to be geared towards email scanning. Is it possible to scan all network traffic with ClamAV? All of the modules appear to be for scanning email and I didn't see mention of scanning all traffic through the gateway.

win32sux 12-20-2004 09:18 AM

Quote:

Originally posted by kegwell
ClamAV appears to be geared towards email scanning.
maybe that was the "original" idea... today you can do much more than just email...

Quote:

Is it possible to scan all network traffic with ClamAV?
YES. it's possible. here's one example which scans lots of traffic:

http://viralator.sourceforge.net/

you can even use it with commercial anti-virus products such as McAfee...

Quote:

All of the modules appear to be for scanning email and I didn't see mention of scanning all traffic through the gateway.
look a little harder, there's lots of options for doing this... there's even a few big corporations that have included clamav in their network appliances and made millions of dollars with it...

http://www.clamav.net/3rdparty.html#pagestart

my point is clamav is just a virus scanning engine - what you scan is up to you...

good luck...


kegwell 12-20-2004 09:44 AM

Thank you very much for the advice. I appreciate the orientation.

not_the_one 12-20-2004 10:37 PM

you could also use a traffic scanning appliance like Fortinet or Symantec


All times are GMT -5. The time now is 03:02 PM.