Configuring Anti-Virus engine settings

To configure Anti-Virus engine settings:

  1. In the main window of the application web interface, open the management console tree and select the Settings section and Protection subsection.
  2. In the Anti-Virus section, click any link to open the Anti-Virus settings window.
  3. In the Protection and heuristic analysis settings group, select one of the following options in the drop-down list Use KSN:
    • Yes, if you want to use KSN.
    • No, if you do not want to use KSN.
  4. In the Protection and heuristic analysis settings group, select one of the following options in the drop-down list Use heuristic analysis:
    • Yes, if you want to use Heuristic Analysis.
    • No, if you do not want to use Heuristic Analysis.
  5. If you have enabled Heuristic Analyzer, in the Protection and heuristic analysis settings group in the Heuristic analysis level list select the level of heuristic analysis.
  6. In the Protection and heuristic analysis settings group, select one of the following options in the I consider some legitimate applications that can be exploited by hackers, to be dangerous for the corporate LAN drop-down list:
    • Yes, if you believe that such applications can be exploited by criminals to harm the computer network of your organization.
    • No, if you do not believe that such applications can be exploited by criminals to harm the computer network of your organization.

    Such legitimate applications include, for example, commercial remote administration utilities, IRC clients, dialers, file downloaders, computer system activity monitors, and password management utilities. Messages in which such applications are detected will be processed according to the rules for infected objects.

  7. If, in the I consider some legitimate applications that can be exploited by hackers, to be dangerous for the corporate LAN list, you selected Yes, in the Protection and heuristic analysis settings group in the Enable detection of some legitimate applications drop-down list select one of the following options:
    • Yes, if you want to enable detection of such applications by Kaspersky Secure Mail Gateway.
    • No, if you want to disable detection of such applications by Kaspersky Secure Mail Gateway.
  8. In the Performance settings group, in the Maximum scanning time field specify the maximum virus scan time in seconds.

    If the virus scan of a message does not finish within the time limit you specified, Kaspersky Secure Mail Gateway:

    • Stops scanning the message (Skip action).
    • Assigns Clean (Clean message) status to the message.
    • Adds the av-status="Clean"label to the message subject.
    • Delivers the message to the recipient.
    • Adds the following entry to the /var/log/maillog event log:

      <scan time and date> <Kaspersky Secure Mail Gateway hostname>: not clean: message-id=<message ID>: relay-ip=<IP address of the computer of the message recipient>: action="Skipped": rules=<rule ID>: size=<message size>: mail-from=<email address of the message sender>: rcpt-to=<email address of the message sender>: av-status="Clean", ap-status="Error", as-status="Error", ma-status="NotScanned, disabled by settings", cf-status="NotScanned, disabled by settings">

  9. In the Performance settings group, in the Maximum scanning level field specify the maximum scanning level for messages scanned by the Anti-Virus engine.
  10. Click the Apply button.

See also

Anti-Virus protection

About computer protection against certain legitimate applications

About virus scan status

Enabling and disabling Anti-Virus protection of messages

Enabling and disabling Anti-Virus scanning for a rule

Setting default values for Anti-Virus engine settings

Configuring actions on messages during Anti-Virus scanning

Configuring tags added to message subjects after Anti-Virus scanning

Configuring Anti-Virus scan restrictions and exclusions

Page top