LinuxQuestions.org
Latest LQ Deal: Latest LQ Deals
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 12-17-2004, 04:12 PM   #1
kegwell
Member
 
Registered: Feb 2004
Distribution: Gentoo Linux
Posts: 46

Rep: Reputation: 15
Network Wide Anti-virus


I was hoping somebody could point me in the correct direction in regards to an open source network wide antivirus solution. I am not concerned with email as we already have virus security in place for that. I am more concerned with virus security for an entire network block. I was thinking of implenting some type of NAT so all traffic from this particular network will go through one machine. What would you recommend to monitor traffic on this machine? Would a client side AV solution be wiser? If so, anything that can be remotely administered?

--Thanks
 
Old 12-17-2004, 05:58 PM   #2
Caeda
Senior Member
 
Registered: Jul 2003
Location: Indiana
Distribution: Suse 6.0+, Mandrake 5.0-10.0, Redhat 6.0-9.0, Gentoo 1.2+, Gnoppix, Knoppix, Sabayon, Ubuntu 5.04+
Posts: 1,811

Rep: Reputation: 45
Are there windows pcs involved here somewhere? If not, why bother with AV?
 
Old 12-19-2004, 08:13 AM   #3
win32sux
LQ Guru
 
Registered: Jul 2003
Location: Los Angeles
Distribution: Ubuntu
Posts: 9,870

Rep: Reputation: 380Reputation: 380Reputation: 380Reputation: 380
try clamav:

http://www.clamav.net/

there's lots of third-party software for it which lets you scan all traffic going through the gateway with it...
 
Old 12-20-2004, 08:38 AM   #4
kegwell
Member
 
Registered: Feb 2004
Distribution: Gentoo Linux
Posts: 46

Original Poster
Rep: Reputation: 15
Yes, 99% of the clients are windows based machines.
 
Old 12-20-2004, 08:43 AM   #5
win32sux
LQ Guru
 
Registered: Jul 2003
Location: Los Angeles
Distribution: Ubuntu
Posts: 9,870

Rep: Reputation: 380Reputation: 380Reputation: 380Reputation: 380
Quote:
Originally posted by kegwell
Yes, 99% of the clients are windows based machines.
well, there you go... you can scan all the network traffic with clamav...

good luck...
 
Old 12-20-2004, 08:47 AM   #6
kegwell
Member
 
Registered: Feb 2004
Distribution: Gentoo Linux
Posts: 46

Original Poster
Rep: Reputation: 15
ClamAV appears to be geared towards email scanning. Is it possible to scan all network traffic with ClamAV? All of the modules appear to be for scanning email and I didn't see mention of scanning all traffic through the gateway.
 
Old 12-20-2004, 09:18 AM   #7
win32sux
LQ Guru
 
Registered: Jul 2003
Location: Los Angeles
Distribution: Ubuntu
Posts: 9,870

Rep: Reputation: 380Reputation: 380Reputation: 380Reputation: 380
Quote:
Originally posted by kegwell
ClamAV appears to be geared towards email scanning.
maybe that was the "original" idea... today you can do much more than just email...

Quote:
Is it possible to scan all network traffic with ClamAV?
YES. it's possible. here's one example which scans lots of traffic:

http://viralator.sourceforge.net/

you can even use it with commercial anti-virus products such as McAfee...

Quote:
All of the modules appear to be for scanning email and I didn't see mention of scanning all traffic through the gateway.
look a little harder, there's lots of options for doing this... there's even a few big corporations that have included clamav in their network appliances and made millions of dollars with it...

http://www.clamav.net/3rdparty.html#pagestart

my point is clamav is just a virus scanning engine - what you scan is up to you...

good luck...


Last edited by win32sux; 12-20-2004 at 09:23 AM.
 
Old 12-20-2004, 09:44 AM   #8
kegwell
Member
 
Registered: Feb 2004
Distribution: Gentoo Linux
Posts: 46

Original Poster
Rep: Reputation: 15
Thank you very much for the advice. I appreciate the orientation.
 
Old 12-20-2004, 10:37 PM   #9
not_the_one
LQ Newbie
 
Registered: Dec 2004
Location: Western Hemisphere
Distribution: Cobalt and Red Hat
Posts: 4

Rep: Reputation: 0
you could also use a traffic scanning appliance like Fortinet or Symantec
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Anti Virus/ Anti Spam for Linux? Sp@rticus Linux - Software 3 11-18-2005 02:17 AM
Boot virus or Anti-Virus? AVG Free Anti-Virus Software problems SparceMatrix Linux - Security 9 08-02-2004 02:35 PM
Best Anti-spam and Anti-virus application? vittibaby Linux - Newbie 6 10-21-2003 07:21 AM
Creating an ultimate anti-virus and anti-spam email gateway markcc Linux - Networking 2 10-08-2003 03:10 AM
Anti trojan and anti virus--Iparmor ppsl Linux - Security 1 12-03-2002 04:33 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 01:40 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration