Avira AntiVir UNIX WebGate manual

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48

Go to page of

A good user manual

The rules should oblige the seller to give the purchaser an operating instrucion of Avira AntiVir UNIX WebGate, along with an item. The lack of an instruction or false information given to customer shall constitute grounds to apply for a complaint because of nonconformity of goods with the contract. In accordance with the law, a customer can receive an instruction in non-paper form; lately graphic and electronic forms of the manuals, as well as instructional videos have been majorly used. A necessary precondition for this is the unmistakable, legible character of an instruction.

What is an instruction?

The term originates from the Latin word „instructio”, which means organizing. Therefore, in an instruction of Avira AntiVir UNIX WebGate one could find a process description. An instruction's purpose is to teach, to ease the start-up and an item's use or performance of certain activities. An instruction is a compilation of information about an item/a service, it is a clue.

Unfortunately, only a few customers devote their time to read an instruction of Avira AntiVir UNIX WebGate. A good user manual introduces us to a number of additional functionalities of the purchased item, and also helps us to avoid the formation of most of the defects.

What should a perfect user manual contain?

First and foremost, an user manual of Avira AntiVir UNIX WebGate should contain:
- informations concerning technical data of Avira AntiVir UNIX WebGate
- name of the manufacturer and a year of construction of the Avira AntiVir UNIX WebGate item
- rules of operation, control and maintenance of the Avira AntiVir UNIX WebGate item
- safety signs and mark certificates which confirm compatibility with appropriate standards

Why don't we read the manuals?

Usually it results from the lack of time and certainty about functionalities of purchased items. Unfortunately, networking and start-up of Avira AntiVir UNIX WebGate alone are not enough. An instruction contains a number of clues concerning respective functionalities, safety rules, maintenance methods (what means should be used), eventual defects of Avira AntiVir UNIX WebGate, and methods of problem resolution. Eventually, when one still can't find the answer to his problems, he will be directed to the Avira service. Lately animated manuals and instructional videos are quite popular among customers. These kinds of user manuals are effective; they assure that a customer will familiarize himself with the whole material, and won't skip complicated, technical information of Avira AntiVir UNIX WebGate.

Why one should read the manuals?

It is mostly in the manuals where we will find the details concerning construction and possibility of the Avira AntiVir UNIX WebGate item, and its use of respective accessory, as well as information concerning all the functions and facilities.

After a successful purchase of an item one should find a moment and get to know with every part of an instruction. Currently the manuals are carefully prearranged and translated, so they could be fully understood by its users. The manuals will serve as an informational aid.

Table of contents for the manual

  • Page 1

    A vir a AntiVir W ebGate | W ebGate Suite www.avira.c om User Manual[...]

  • Page 2

    Avira GmbH Avira AntiVir WebGate 2 Contents 1 About this Manual ............ ........................................................ ........... 4 1.1 Introducti on ....................................................................................................... 4 1.2 The Structure of the Manual ..............................................[...]

  • Page 3

    Avira GmbH Avira AntiVir WebGate 3 8 Appendix ................ ................. ................................ .............. ........... 46 8.1 Glossary ............................................................................................................. 46 8.2 Further Inform ation .......................................................[...]

  • Page 4

    About this Manual Avira GmbH Avira AntiVir WebGate 4 1A b o u t t h i s M a n u a l In this Chapter you can find an overview of the structure and contents of this manual. After a short introduction, you can read information about the following issues: z The S tructure of the Manual – P age 5 z Signs and Symbols – Page 5 1.1 Introduction We have[...]

  • Page 5

    About this Manual Avira GmbH Avira AntiVir WebGate 5 1.2 T he Structure of the Manual The manual of your AntiVir software co nsists in a number of Chapters, bringing you the following information: 1.3 Signs and S ymbols The manual uses the foll owing signs and symbols: Chapter Cont ents 1 About this Manual The structure of the manual, signs and sym[...]

  • Page 6

    About this Manual Avira GmbH Avira AntiVir WebGate 6 For improved legibility and cl ear marking, the following types of emphasis will also be used in the text: 1.4 Abbreviations The manual uses the following abbreviations: Emphasis in text E xplanation Ctrl+Alt Key or key combination /usr/lib/AntiVir/avupdate Path and filename ls /usr/lib/AntiVir U[...]

  • Page 7

    Product Information Avira GmbH Avira AntiVir WebGate 7 2P r o d u c t I n f o r m a t i o n Internet connection is an underestimated invasion doorway for malware on your computer. If you transfer unfiltered data f rom the Internet on your system, you can spread all types of malware throughout the entire network. Avira AntiVir WebGate is a reliable [...]

  • Page 8

    Product Information Avira GmbH Avira AntiVir WebGate 8 2.1 Featur es Avira AntiVir WebGate support s a variety of configurati on settings for controlling Internet data transfer. T he essential features are: • Ex t ended access contr ol, f or setting r ules t o allow tunneling f or cer tain types of requests and r esponses. • Local URL f ilterin[...]

  • Page 9

    Product Information Avira GmbH Avira AntiVir WebGate 9 • Newsletter Service (per email) • Internet U pd ate Ser vice for pr og ram files and VDF After installing an AntiVir product, you can read the information on your current license, using the license tool av li n fo : X Cha ng e t o /usr/lib/AntiVir and call ./avlinfo Use avlinfo -h to get i[...]

  • Page 10

    Product Information Avira GmbH Avira AntiVir WebGate 10 categories, such as Violenc e , Gam bl ing , Er otic etc. To determine the categories for a certain URL, the Web Access and Content Control library is us ed. (This module is only activated with the license for Avira WebGate Suite .) To find out more details about the Web Ac cess and Content Co[...]

  • Page 11

    Installation Avira GmbH Avira AntiVir WebGate 11 3 Installation You can find the current version of Avira AntiVir WebGate on our website . Avira AntiVir WebGate is supplied as pa cked archive. This archive contains the AntiVir Engine and VDF files, the Avir a Updater, the WebGate Main Program and the optional SMC plug-in. You are guided through the[...]

  • Page 12

    Installation Avira GmbH Avira AntiVir WebGate 12 Unpacking Pr ogram Files X Go to the tempor ar y director y : cd /tmp X Unpack the AntiVir archive : tar -xzvf antivir-webgate-prof-<version>.tar.gz  in the temporar y direct or y will then appear antivir-web gate-pr of -<version> . 3.3 Licensing You must have a license for AntiVir W e[...]

  • Page 13

    Installation Avira GmbH Avira AntiVir WebGate 13 3.4 Installing A vira AntiVir W ebGate Avira AntiVir WebGate installation is performed automatically using an installation script. This script performs the following tasks: • Checks inte grit y of the installation files • Check s for the r equired permissions for installation • Check s for exis[...]

  • Page 14

    Installation Avira GmbH Avira AntiVir WebGate 14  After you type the path to the key file, the installer continues with updates configuration: X Type Y .  Then the script can create a cron task for automatic Scanner updates: X Type Y , if you want to create these cr on tasks.  Then eventually select the interval to check for updates: X Typ[...]

  • Page 15

    Installation Avira GmbH Avira AntiVir WebGate 15  The program is installed. T hen you are asked if you want to create a link to avw e b g at e and if the Updater should be au tomatically activated at system start: X Confirm with Enter . Y ou can change these settings later .  The automatic system start is configured:  Then you are asked if[...]

  • Page 16

    Installation Avira GmbH Avira AntiVir WebGate 16 3.5 Reinstalling and uninstalling AntiVir You can re-launch the inst allation script anytime. There are more situations possible: • Installing a new version (upgr ade). The installation script che cks the previous version and installs the necessar y new components. T he config uration set - tings a[...]

  • Page 17

    Installation Avira GmbH Avira AntiVir WebGate 17 ./uninstall --product=Webgate  The script starts uninstallin g the product, asking you st ep by step, if you want to keep backups for the licen se file, for the configuration files and logfiles; it can also remove the cronjobs yo u made for WebGate and Scanner. X Answer the questions with y or n a[...]

  • Page 18

    Configuration Avira GmbH Avira AntiVir WebGate 18 4 Config uration You can configure Avira AntiVir WebGate for optimum performance. The most common settings are suggested in this Chapter. You can modify these settings anytime, to adjust WebGate to your requirements. You will be guided step by step through the configuration process: z In Monitoring [...]

  • Page 19

    Configuration Avira GmbH Avira AntiVir WebGate 19 W ebGate without Pro xy Ser ver (Network Configuration 0) If there is no proxy server, WebGate stands between Clients and the Internet. It can be installed directly on Clients or on another computer. WebGate directs the Clients’ enquiries to the Internet and sc ans the answer from the Internet. Th[...]

  • Page 20

    Configuration Avira GmbH Avira AntiVir WebGate 20 The real settings can differ from those giv en in the example, but for a correct configuration, the settings in avw e b g at e. c on f must be compatible with the Client’s browser configuration. W ebGate between Client and Pro xy Ser ver (Network Configuration 1) In this configuration, the other p[...]

  • Page 21

    Configuration Avira GmbH Avira AntiVir WebGate 21 X Make the following settings in avwe b g a te . co n f (ex ample): HTTPPort 3128  Now, the Clients will communicate through WebGate for HTTP and FTP inquiries, not directly through the original proxy server. The browser settings on the Client computers must not be changed. X Enter the f ollowing[...]

  • Page 22

    Configuration Avira GmbH Avira AntiVir WebGate 22 The example assumes the following configuration of the proxy server: host proxy.mycompany.com serverport 3128 So the proxy server responds on port 3128. X Make the following settings in avwe b g a te . co n f (ex ample): HTTPPort 8080 X Configure the other proxy ser ver , so that it does not directl[...]

  • Page 23

    Configuration Avira GmbH Avira AntiVir WebGate 23 If you modify the proxy server’s port, you have to adapt the se ttings of the Clients’ browsers, which access the proxy. It is usually easier to keep the proxy settings and to adapt the WebGate settings, just like in the above example. 4.2 Monitoring F TP Traffic WebGate can also be set as real [...]

  • Page 24

    Configuration Avira GmbH Avira AntiVir WebGate 24 On login, the FTP Client should be used just as before, i. e. when it was not using WebGate. WebGate acts as p roxy between FTP Client an d FTP server and scans the transferred data. Optionally, WebGate allows a parent FTP p roxy. For example, it can be set in avw e b g at e. c on f as follows: FTPP[...]

  • Page 25

    Configuration Avira GmbH Avira AntiVir WebGate 25 Scanning Outgoing Data T r affic (Request Modif ication) The ICAP Client sends an HTTP request to WebGate (ICAP-Serv er) for scanning. If the data is not infected, it is returned to the ICAP Client and from there it is sent to the destination server. If t he request is blocked (i. e. in case of a vi[...]

  • Page 26

    Configuration Avira GmbH Avira AntiVir WebGate 26 4.4 Config uration Files This part describes the contents of Av ira AntiVir WebGate configuration files: • /etc/avwebgate.conf - Product configuration • /etc/avwebgate-s canner .conf - Scanner configuration • /etc/avira/a vupdate.conf - U pdater configuration • /etc/avwebgate.acl - Access Co[...]

  • Page 27

    Configuration Avira GmbH Avira AntiVir WebGate 27 WebGate should assume after start (and thus turning in t he root permissions). User 65534 Group antivir WebGate must first start as root. If you do not want this, yo u must specify the values for User and Group in the file /etc/a vwebgate.conf . ScannerL isten Address WebGate no longer starts the SA[...]

  • Page 28

    Configuration Avira GmbH Avira AntiVir WebGate 28 • If the option RefreshInterval is deactivated or the Cl ient is not a bro wser , (tempor ar y) HT TP redirects ar e se nt to the Client . Thus , the C lient is c yclically redir ected to a dynamic-gener ated URL , intercepted by W ebGate in order t o av oid the timeout. Default : RedirectInterval[...]

  • Page 29

    Configuration Avira GmbH Avira AntiVir WebGate 29 directory contains for exampl e, the files during scanning. TemporaryDir /tmp (/var/tmp for Solaris binaries) Arc hiveScan Scanning archives: By default, all files in archives are unpa cked on access and scanned, according to the settings for ArchiveMaxSize , ArchiveMaxRecursion and ArchiveMaxRatio [...]

  • Page 30

    Configuration Avira GmbH Avira AntiVir WebGate 30 Bloc k Ex tensi ons Blocking certain fi le extensions: WebGate can block files that have certain extensions. It will also apply for file names in archives. BlockExtensions exe scr pif Move Concerning FilesT o Quarantine directory : By default, blocked files are deleted. But you can specify a quar an[...]

  • Page 31

    Configuration Avira GmbH Avira AntiVir WebGate 31 direct communication partn ers’ and not the address of the computer issuing the request. If the AddXForwardedForHeader option is active, WebGate adds a header field (X-Forwarded-For) to the HTTP request or adds the IP address of the Client it received the request from. In this way Web Gate can for[...]

  • Page 32

    Configuration Avira GmbH Avira AntiVir WebGate 32 Bloc k Categor ies URL filtering: First, the access control (ACL) rules are evaluated, which means a rule allowing tunneling for a request will not be blocked by URL filters. Connections that are not tunneled would still pass through the URL filter module, similar to the scanning behavior. Then, the[...]

  • Page 33

    Configuration Avira GmbH Avira AntiVir WebGate 33 Heu r i s ti c s Macro Macrovirus Heuristics: Activates the heuristics for macroviruses in documents. This option is activated by default: HeuristicsMacro yes Heu r i s ti c s Lev el Win32-Heuristics: Sets the detection level of Win32- Heuristics. available values are 0 (off), 1 (low), 2 (medium) an[...]

  • Page 34

    Configuration Avira GmbH Avira AntiVir WebGate 34 In /etc/avwebgate.conf: • Change the option User/Group Socket P ermissions The owner and permissions of the scanner backend's socket. SocketPermissions 0600 ListenAddress ListenAddress (in avw e b g at e - s c a n ne r.c on f ) and ScannerListenAddress (in avw e b g at e. c on f ) specify how[...]

  • Page 35

    Configuration Avira GmbH Avira AntiVir WebGate 35 kept up to date. With Avira Updater you can update Av ira software on your computers, using Avira update servers. To configure the update process, use the options in /etc/avira/a vupdate.conf described below. All parameters from av u pd at e. c on f can be passed to the Updater via command line. For[...]

  • Page 36

    Configuration Avira GmbH Avira AntiVir WebGate 36 notify-when= email-to The recipient of notification emails. email-to=root@localhost Setting pro xy configuration for updat es proxy ... If the machine uses a HTTP proxy server, proxy configuration settings must be specified in order to make Internet updates. proxy-host= proxy-port= proxy-username= p[...]

  • Page 37

    Configuration Avira GmbH Avira AntiVir WebGate 37 4.5 T emplates Configuration If you have a valid license file, you may customize various noti fication web pages and emails generated by Avira AntiVir WebGate. WebGate will send these for example, in case of detectin g viruses or unwanted programs: alert, blocked, error or progress template. These t[...]

  • Page 38

    Configuration Avira GmbH Avira AntiVir WebGate 38 Email T emp lat es 4.6 T esting Avira AntiVir W ebGat e After completing the installation and conf iguration, you can test the functionality of AntiVir WebGate using a test virus. This will not cause any damage, but it will force the security program to re act when the computer is scanned. T esting [...]

  • Page 39

    Operation Avira GmbH Avira AntiVir WebGate 39 5O p e r a t i o n After concluding installa tion and configurati on an d Avira AntiVir WebGate is running, WebGate guarantees continuous monitoring of your system. During operation you might have to make occasion al changes in settings, as described in Configuration – Page 18. This Chapter is divided[...]

  • Page 40

    Operation Avira GmbH Avira AntiVir WebGate 40 Restar ting AntiVir W ebGat e This is used, for example, after making changes in configuration scripts. X Type: /usr/lib/AntiVir/avwebgate restart  The program restarts after s howing the following message: Checking AntiV ir W ebGa te status X Type: /usr/lib/AntiVir/avwebgate status  The program s[...]

  • Page 41

    Operation Avira GmbH Avira AntiVir WebGate 41 Submitting Infected Files to A v ira GmbH X Please send us the malware or suspicious files that our pr oduct does not yet recognize or remove. Send us the vir us or file packed ( gzip, W inZIP , PKZip, Arj) in the attachment of a n email to virus@antivir .de. When packing, use the password virus . This [...]

  • Page 42

    Updates Avira GmbH Avira AntiVir WebGate 42 6U p d a t e s With Avira Updater you can update Av ira software on your computers, using Avira update servers. The program can be configured eit her by editing the configuration file (see Updater Configuration in avupdate.conf – Page 34), or by using parameters in the command line. It is recommended to[...]

  • Page 43

    Updates Avira GmbH Avira AntiVir WebGate 43 As [product] , you can use: • Scanner - (rec ommended) to update the scanner , eng ine and vdf files. • WebGate - complete update (W ebGate, sc anner , eng ine and vdf files). X Star t the upd ate pr ocess to test the settings : /usr/lib/AntiVir/avupdate --product=[product] where [product] takes the s[...]

  • Page 44

    Service Avira GmbH Avira AntiVir WebGate 44 7S e r v i c e 7.1 Suppor t Support Ser v ice Our Webpage http://www .a vira.com contains all the necessa ry information on our extensive support service. The competence and experience of our deve lopers is at your disposal. The experts from Avira answer your questions and help you with difficult technica[...]

  • Page 45

    Service Avira GmbH Avira AntiVir WebGate 45 7.3 Contact Address Avira GmbH Lindauer Strasse 21 D-88069 Tettnang Germany Interne t You can find further information about us and our prod ucts by visiting http://www .avira.com .[...]

  • Page 46

    Appendix Avira GmbH Avira AntiVir WebGate 46 8 A ppendix 8.1 Glossar y Item Meaning Backdoor (BDC) A backdoor is a program infilt rated in order to steal data from the computer, without the user’s knowledge. This program is manipulated by third-parties using a remote backdoor-control software, over the Internet or network. AntiVir detects backdoo[...]

  • Page 47

    Appendix Avira GmbH Avira AntiVir WebGate 47 8.2 Fur ther Information You can find further information on vi ruses, worms, macro viruses and other unwanted programs at http://www .a vira.com . Script A text file containing commands to be executed by th e system. (similar to batch files in DOS) SMP (Symmetric Multi Processing) Unix SMP: Unix version[...]

  • Page 48

    Appendix Avira GmbH Avira AntiVir WebGate 48 8.3 Golden Rules for Pr otection Against Vir uses X Always keep bo ot f loppy -disks , for your network ser ver and for your workstations. X Always remove f loppy -disk s from the drive after finishing the work . Even if they have no ex ecutable programs, disk s can contain program code in the boot secto[...]