Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Is it Possible that the Firewall won't detect eicar ? ( Malware-Scanner activated..)

Hi

Just setted up my new Sophos XG Firewall at home, but when I test the malware-scanner ( downloading EICAR-File) it won't be detected. malware-scanner is active, also in rule is it "on" 

Any help is kindly appreciated!

Regards



This thread was automatically locked due to age.
Parents Reply Children
  • The Eicar test files are not being blocked for me as well. I have the services defined as "ANY" but it still does not block the download. I'm concerned that the AV scanning is not working at all. 

  • Try manually putting YOUR XG Firewall LAN address port 3128 in your browser configuration for proxy settings and see if it works.
    Also can you please post your rule that is failing.
  • Interestingly, for me they are being blocked if I try and download via Chrome. However, using IE they are NOT blocked. This is without changing the proxy to go through the XG firewall.

    Not sure why Chrome would work and IE wouldn't, must something in the way Sophos sees the traffic in the different browsers.
  • I can acknowledge this behavior
  • Sorry posted twice. Please see other message.

  • I can't confirm that. My network rule restricts the services to web ports (80 and 443) and ftp ports (21,990). Furthermore I am using the firewall in transparent proxy mode. In my setup the XG firewall is able to detect the eicar test file from eicar.org. See screenshots below.

  • >>Not sure why Chrome would work and IE wouldn't, must something in the way Sophos sees the traffic in the different browsers.

    In my setup it also works with IE. See screenshot below.

  • dempie said:
    My network rule restricts the services to web ports (80 and 443) and ftp ports (21,990). Furthermore I am using the firewall in transparent proxy mode.

    The bug that I filed was originally for non transparent traffic. But as you can see something is not right with the transparent intercept of traffic also. In any case, this probably won't get fixed till someone calls support.

  • Billybob said:

    The bug that I filed was originally for non transparent traffic. But as you can see something is not right with the transparent intercept of traffic also. In any case, this probably won't get fixed till someone calls support.

    Best Regards.
  • Hi and thanks for the detailed response. I am not using XG at the moment so what I am writing is from memory only. Since my detailed report on astaro.org is also gone, I will try to recreate the scenario from memory. community.sophos.com/.../58158

    1.Client using XG as gateway and using transparent mode --- Worked in chrome with services defined. I didn't Try IE.

    2. Client using XG as gateway and using port 3128 in browser proxy config... Bypasses traffic unless use ANY in services.

    3. Changing proxy port on XG to 8080 and using 8080 in browser also fails unless ANY is used for traffic.

    The traffic completely bypasses the proxy (no proxy logs) when I tried different services. I only tested with ONE rule. Masq Internal to external, services ftp, http, scan for malware, user not defined. The traffic is not logged but bypasses XG completely for some reason. I did not try with port 3128 in allowed services as to me that would indicate that I want internal clients to be able to use proxy (port 3128) offered by external websites.

    Regards