2.3. ANTIVIRUS
These log messages refer to the ANTIVIRUS (Anti-virus related events) category.
2.3.1. virus_found (ID: 05800001)
Default Severity
WARNING
Log Message
Virus found in file <filename>. Virus Name: <virusname>. Signature:
<virussig>. Advisory ID: <advisoryid>.
Explanation
A virus has been detected in a data stream. Since anti-virus is running
in protect mode, the data transfer will be aborted in order to protect the
receiver.
Gateway Action
block_data
Recommended Action
If the infected file is local, run anti-virus program to clean the file.
Revision
1
Parameters
filename
virusname
virussig
advisoryid
[layer7_srcinfo]
[layer7_dstinfo]
Context Parameters
ALG Module Name
ALG Session ID
Connection
2.3.2. virus_found (ID: 05800002)
Default Severity
WARNING
Log Message
Virus found in file <filename>. Virus Name: <virusname>. Signature:
<virussig>. Advisory ID: <advisoryid>.
Explanation
A virus has been detected in a data stream. Since anti-virus is running
in audit mode, the data transfer will be allowed to continue.
Gateway Action
allow_data
Recommended Action
If the infected file is local, run anti-virus program to clean the file.
Revision
1
Parameters
filename
virusname
virussig
advisoryid
[layer7_srcinfo]
[layer7_dstinfo]
Context Parameters
ALG Module Name
ALG Session ID
Connection
2.3. ANTIVIRUS
Chapter 2. Log Message Reference
138
Summary of Contents for DFL-210 - NetDefend - Security Appliance
Page 25: ...List of Tables 1 Abbreviations 28 25...
Page 26: ...List of Examples 1 Log Message Parameters 27 2 Conditional Log Message Parameters 27 26...
Page 36: ...1 3 Severity levels Chapter 1 Introduction 36...
Page 195: ...2 12 6 route_removed ID 01100006 Chapter 2 Log Message Reference 195...
Page 409: ...2 40 19 scp_failed_not_admin ID 04704000 Chapter 2 Log Message Reference 409...
Page 476: ...2 49 14 zd_block ID 03800014 Chapter 2 Log Message Reference 476...