Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Bug? Sophos XG does not block EICAR file in realtime since last update

FormerMember
FormerMember

Hi,

 

since last update, Sophos XG does not block EICAR files in real-time scan mode anymore!

The file is downloaded without scanning!

In Batch mode the file is blocked as before!

 

Regards Meghan



This thread was automatically locked due to age.
Parents Reply Children
  • I can confirm that changing from Real Time to Batch blocks the EICAR file from downloading.  Change it back to Real Time and the file downloads but is apparently stripped out and empty. 

  • FormerMember
    0 FormerMember in reply to Bill Roland

    Max. scan size: 1536mb

    Engines: dual scan

     

    I am downloading the testfiles from www.eicar.org

     

    Regards Meghan

  • Is the HTTPS and HTTP scanning enabled in the firewall rule that handles the internet traffic? Also, check the AV pattern updates are up2date.

    Thanks

    Sachin Gurung
    Team Lead | Sophos Technical Support
    Knowledge Base  |  @SophosSupport  |  Video tutorials
    Remember to like a post.  If a post (on a question thread) solves your question use the 'This helped me' link.

  • FormerMember
    0 FormerMember in reply to sachingurung

    Hi Sachin,

    yes the scanning functions are enabled.

     

    Regards Meghan

  • Please be aware that when using Real Time scanning, the majority of the time you will not see a block page.  You will instead get an incomplete download.

    Real Time scanning basically sends the 200 OK response the client as soon as it gets it from the server.  Then as the file is received from the server it stores it on disk and simultaneous send it to the client.  As the last 1K of data is received from the server, it is withheld from the client.  Now the XG has the whole file and scans it.  If clean, it sends the last 1K.  If a virus, it kills the connection to the client so that it is an incomplete download.

    With small files, the same logic applies but because it happens so quickly there are differences.  For example, the client may get a 200 OK and no content.  The client doesn't report it as a failed download.

    Either way, the XG Malware logs should show that a virus was detected.

    Can you confirm - when you say that you can download eicar - do you actually see the full malware test string in the final file that is saved to the client harddrive?  Does the XG log a virus found?

     

     

  • FormerMember
    0 FormerMember in reply to Michael Dunn

    Hello Michael Dunn,

     

    as i've written before, the Eicar files are without any content/code.

    In the EICAR.zip file, there is no file inside the zip, and in both eicar.txt and eicar.com, there is no code inside the files, thay are empty.

    What I'am concerned about, is that EICAR is NOT logged as virus by XG.

     

    Regards Meghan

  • So SFOS is blocking correctly, this is just a logging problem.

    So to confirm:
    You click on Log Viewer.  In the pop-up you say View logs for Malware.  There is nothing there?

    Just as a double check:
    Go to System Services, Log Settings.  Under Anti-virus, everything is checked.

    If everything looks good but still no logs....  I'm not sure.  reboot?

  • FormerMember
    0 FormerMember in reply to Michael Dunn

    Hi,

    I've just checked these things, and no Virus is logged.

    The log settings are correct.

    I've tried rebooting, but nothing changed.

    Regards Meghan

  • I cannot think of anything that would make logging work when in Batch mode and logging not work when in Real Time.

    I don't think there is anything else in the forums that could help...  Other people have confirmed it works for them.  If you wanted to follow up further, I would contact Sophos Support.