[ Contents] [ Prev] [ Next] [ Index] [ Report an Error]

Configuring Express Antivirus

You can use J-Web or the CLI to configure the express antivirus feature. When configuring express antivirus protection, you must first create the antivirus custom objects you are using. Those custom objects may include the MIME pattern list, MIME exception list, and the filename extension list. Once you have created your custom objects, you can configure express antivirus protection, including fallback options, intelligent prescreening, and content size limits.

This topic contains:

Configuration Overview

For each UTM feature, you should configure feature parameters in the following order:

  1. First configure UTM custom objects (if any), for the feature in question. Custom objects are global parameters for UTM features. This means that configured custom objects apply to all UTM policies where applicable, rather than only to individual policies.

    The CLI commands for setting antivirus custom objects are:

    user@host# set security utm custom-objects mime-pattern
    user@host# set security utm custom-objects url-pattern
    user@host# set security utm custom-objects custom-url-category
  2. Configure main feature parameters, called feature profiles.

    The CLI command for setting antivirus feature profiles is:

    user@host# set security utm feature-profile anti-virus juniper-exress-engine
  3. Configure a UTM policy for each protocol and attach this policy to a profile.

    CLI commands for configuring a UTM policy for HTTP (for example) and attaching that policy to a profile are:

    user@host# set security utm utm-policy <name>
    user@host# set security utm utm-policy utmp3 anti-virus http-profile http1
  4. Attach the UTM policy to a firewall security policy.

    The CLI command for attaching a UTM policy to a security policy is:

    user@host# set security policies
    user@host# set security policies from-zone trust to-zone untrust policy p3 then permit application-services utm-policy utmp3

J-Web Configuration

To configure express antivirus protection using the J-Web configuration editor, you must first create your custom objects (MIME pattern list, URL pattern list, and custom URL category list).

Configure a MIME pattern list custom object as follows (see MIME White List for overview information on MIME white lists):

  1. Select Configure>Security>UTMCustom Objects.
  2. From the MIME Pattern List tab, click Add to create MIME pattern lists.
  3. In the Add MIME Pattern pop-up window, next to MIME Pattern Name, enter a unique name for the list you are creating.

    Keep in mind that you are creating a MIME white list and a MIME exception list (if necessary). Both MIME lists appear in the MIME Whitelist and Exception MIME Whitelist fields when you configure antivirus. Therefore, the MIME list names you create should be as descriptive as possible.

  4. Next to MIME Pattern Value, enter the MIME pattern.
  5. Click Add to add your MIME pattern to the Values list box.

    Within this box, you can also select an entry and use the Delete button to delete it from the list. Continue to add MIME patterns in this manner.

  6. Optionally, create a new MIME list to act as an exception list.

    The exception list is generally a subset of the main MIME list.

  7. Click OK to save the selected values as part of the MIME list you have created.
  8. If the configuration item is saved successfully, you receive a confirmation and you must click OK again. If it is not saved successfully, you can click Details in the pop-up window that appears to discover why.

Configure a URL Pattern List Custom Object as follows:

Note: Because you use URL pattern lists to create custom URL category lists, you must configure URL pattern list custom objects before you configure a custom URL category list.

  1. Select Configure>Security>UTM>Custom Objects.
  2. From the URL Pattern List tab, click Add to create URL pattern lists.
  3. Next to URL Pattern Name, enter a unique name for the list you are creating. This name appears in the Custom URL Category List Custom Object page for selection.
  4. Next to URL Pattern Value, enter the URL or IP address you want added to list for bypassing scanning.

    Note: URL pattern wildcard support—The wildcard rule is as follows: \*\.[]\?* and you must precede all wildcard URLs with http://. You can only use “*” if it is at the beginning of the URL and is followed by a “.”. You can only use “?” at the end of the URL.

    The following wildcard syntax IS supported: http://*.juniper.net, http://www.juniper.ne?, http://www.juniper.n??. The following wildcard syntax is NOT supported: *.juniper.net , www.juniper.ne?, http://*juniper.net, http://*.

  5. Click Add to add your URL pattern to the Values list box. The list can contain up to 8192 items. You can also select an entry and use the Delete button to delete it from the list. Continue to add URLs or IP addresses in this manner.
  6. Click OK to save the selected values as part of the URL pattern list you have created.
  7. If the configuration item is saved successfully, you receive a confirmation and you must click OK again. If it is not saved successfully, you can click Details in the pop-up window that appears to discover why.

Configure a custom URL category list custom object using the URL pattern list you created as follows (see URL White List for overview information on URL white lists):

  1. Select Configure>Security>UTM>Custom Objects.
  2. From the URL Category List tab, click Add to create URL category lists.
  3. Next to URL Category Name, enter a unique name for the list you are creating. This name appears in the URL Whitelist list when you configure antivirus global options.
  4. In the Available Values box, select a URL Pattern List name from the list for bypassing scanning and click the right arrow button to move it to the Selected Values box.
  5. Click OK to save the selected values as part of the custom URL list you have created.
  6. If the configuration item is saved successfully, you receive a confirmation and you must click OK again. If it is not saved successfully, you can click Details in the pop-up window that appears to discover why.

Now that your custom objects have been created, you can configure the antivirus feature profile.

  1. Select Configure>Security>UTM>Global options.
  2. In the Anti-Virus tab, next to MIME whitelist, select the custom object you created from the list.
  3. Next to Exception MIME whitelist, select the custom object you created from the list.
  4. Next to URL Whitelist, select the custom object you created from the list.
  5. In the Engine Type section, select the type of engine you are using.

    For express antivirus protection, you should select Juniper Express.

  6. Next to Pattern update URL, enter the URL for the pattern database in the box. Note that the URL is http://update.juniper-updates.net/EAV/<device version> and you should not change it. See Updating Antivirus Patterns for more information.
  7. Next to Pattern update interval, enter the time interval for automatically updating the pattern database in the box.

    The default for express antivirus checking is once per day. See Updating Antivirus Patterns for more information.

  8. Select whether you want the pattern file to update automatically (Auto update) or not (No Auto update).
  9. Click OK to save the selected values.
  10. If the configuration item is saved successfully, you receive a confirmation and you must click OK again. If it is not saved successfully, you can click Details in the pop-up window that appears to discover why.
  11. Select Anti-Virus, under Security, in the left pane.
  12. Click Add in the right window to create a profile for the antivirus Juniper Express Engine.

    To edit an existing item, select it and click Edit.

  13. In the Main tab, next to Profile name, enter a unique name for this antivirus profile.
  14. Select the Profile Type.

    In this case, select Juniper Express.

  15. Next to Trickling timeout, enter timeout parameters.

    Note that trickling only applies to HTTP. HTTP trickling is a mechanism used to prevent the HTTP client or server from timing-out during a file transfer or during antivirus scanning. See HTTP Trickling for overview details.

  16. Next to Intelligent prescreening, select Yes or No.

    See Intelligent Prescreening for details.

    Note: Intelligent prescreening is only intended for use with non-encoded traffic. It is not applicable for mail protocols (SMTP, POP3, IMAP, and HTTP POST).

  17. Next to Content Size Limit, enter content size parameters.

    The content size check occurs before the scan request is sent. The content size refers to accumulated TCP payload size. See Content Size Limits for details.

  18. Next to Scan engine timeout, enter scanning timeout parameters.

    See Scanning Timeout for overview details.

  19. Select the Fallback settings tab.
  20. Next to Default (fallback option), select Log and permit or Block from the list.

    Note that in most cases, Block is the default fallback option. See Fallback Options for a detailed overview of this feature and each fallback category.

  21. Next to Decompress Layer (fallback option), select Log and permit or Block from the list.
  22. Next to Content Size (fallback option), select Log and permit or Block from the list.
  23. Next to Engine Not Ready (fallback option), select Log and permit or Block from the list.
  24. Next to Timeout (fallback option), select Log and permit or Block from the list.
  25. Next to Out of Resource (fallback option), select Log and permit or Block from the list.
  26. Next to Too Many Requests (fallback option), select Log and permit or Block from the list.
  27. Select the Notification options tab.
  28. In the Fallback block section, next to Notification type, select Protocol Only or Message to select the type of notification that is sent when a fallback option of block is triggered.
  29. Next to Notify mail sender, select Yes or No.
  30. If you selected Yes, next to Custom Message, enter text for the message body of your custom message for this notification (if you are using a custom message).
  31. Next to Custom message subject, enter text to appear in the subject line of your custom message for this notification (if you are using a custom message).
  32. In the Fallback non block section, next to Notify mail recipient, select Yes or No.
  33. If you selected Yes, next to Custom Message, enter text for the message body of your custom message for this notification (if you are using a custom message).
  34. Next to Custom message subject, enter text to appear in the subject line of your custom message for this notification (if you are using a custom message).
  35. Select the Notification options cont tab.
  36. In the Virus detection section, next to Notification type, select Protocol Only or Message to select the type of notification that is sent when a fallback option of block is triggered.

    See Protocol-Only Notifications for overview information.

  37. Next to Notify mail sender, select Yes or No.
  38. If you selected Yes, next to Custom Message, enter text for the message body of your custom message for this notification (if you are using a custom message).
  39. Next to Custom message subject, enter text to appear in the subject line of your custom message for this notification (if you are using a custom message).

    The limit is 255 characters.

  40. Click OK.
  41. If the configuration item is saved successfully, you receive a confirmation and you must click OK again. If it is not saved successfully, you can click Details in the pop-up that appears window to discover why.

    Note: You create a separate antivirus profile for each antivirus protocol. These profiles may basically contain the same configuration information, but when you are creating your UTM policy for antivirus, the UTM policy configuration page provides separate antivirus profile selection fields for each supported protocol.

Next, you configure a UTM policy for express antivirus to which you attach the antivirus profile you have configured.

  1. Select Configure>Security>Policy>UTM Policies.
  2. From the UTM policy configuration window, click Add to configure a UTM policy.

    The policy configuration pop-up window appears.

  3. Select the Main tab in pop-up window.
  4. In the Policy name box, enter a unique name for the UTM policy you are creating.
  5. In the Session per client limit box, enter a session per client limit from 0 to 20000 for this UTM policy.
  6. For Session per client over limit , select one of the following: Log and permit or Block.

    This is the action the device takes when the session per client limit for this UTM policy is exceeded.

  7. Select the Anti-Virus profiles tab in the pop-up window.
  8. Select the appropriate profile you have configured from the list for the corresponding protocol listed.
  9. Click OK.
  10. If the policy is saved successfully, you receive a confirmation and you must click OK again. If the profile is not saved successfully, you can click Details in the pop-up window that appears to discover why.

Next, you attach the UTM policy to a security policy that you create.

  1. Select Configure>Security>Policy>FW Policies.
  2. From the Security Policy window, click Add to configure a security policy with UTM.

    The policy configuration pop-up window appears.

  3. In the Policy tab, enter a name in the Policy Name box.
  4. Next to Default Policy Action, select one of the following: Deny-All or Permit-All.
  5. Next to From Zone, select a zone from the list.
  6. Next to To Zone, select a zone from the list.
  7. Under Zone Direction, click Add a Policy.
  8. Choose a Source Address.
  9. Choose a Destination Address.
  10. Choose an Application. Do this by selecting junos-<protocol> (for all protocols that support antivirus scanning) in the Application Sets box and clicking the right arrow —> button to move them to the Matched box.
  11. Next to Policy Action, select Permit.

    Note: When you select Permit for Policy Action, several additional fields become available in the Applications Services tab, including UTM Policy.

  12. Select the Application Services tab in the pop-up window.
  13. Next to UTM Policy, select the appropriate policy from the list. This attaches your UTM policy to the security policy.

    Note: There are several fields on this page that are not described in this section. See the Security Policies section for detailed information on configuring security policies and all the available fields.

  14. Click OK.
  15. If the policy is saved successfully, you receive a confirmation and you must click OK again. If the profile is not saved successfully, you can click Details in the pop-up window that appears to discover why.

    You must activate your new policy to apply it.

J-Web Point and Click CLI Configuration

To configure antivirus protection using the J-Web Point and Click CLI, you must first create your custom objects (MIME Pattern List, URL Pattern List, and Custom URL Category List).

Configure a MIME Pattern List Custom Object as follows (see MIME White List for overview information on MIME white lists):

  1. Select Configure>CLI Tools>Point and Click CLI.
  2. Next to Security, click Edit.
  3. Next to Utm, click Configure.
  4. Next to Custom objects, click Configure.
  5. Next to Mime pattern, click Add new entry.
  6. Next to Name, enter a unique name for the MIME list you are creating.
  7. Next to Value, click Add new entry.
  8. Next to Value, enter the MIME pattern.
  9. Click OK. See Figure 126.

    Figure 126: Custom Object, MIME Pattern Configuration, Point and Click CLI Configuration

    Image ve_mime_pattern.gif

Configure a URL Pattern List Custom Object as follows:

  1. Select Configure>CLI Tools>Point and Click CLI.
  2. Next to Security, click Edit.
  3. Next to Utm, click Configure.
  4. Next to Custom objects, click Configure.
  5. Next to Url pattern, click Add new entry.
  6. Next to Name, enter a unique name for the list you are creating.
  7. Next to Value, click Add new entry.
  8. Next to Value, enter the URLs or IP addresses you want added to list for bypassing scanning.

    Note: URL pattern wildcard support—The wildcard rule is as follows: \*\.[]\?* and you must precede all wildcard URLs with http://. You can only use “*” if it is at the beginning of the URL and is followed by a “.”. You can only use “?” at the end of the URL.

    The following wildcard syntax IS supported: http://*.juniper.net, http://www.juniper.ne?, http://www.juniper.n??. The following wildcard syntax is NOT supported: *.juniper.net , www.juniper.ne?, http://*juniper.net, http://*.

  9. Click OK. See Figure 127.

    Figure 127: Custom Object, URL Pattern Configuration, Point and Click CLI Configuration

    Image ve_url_pattern.gif

Configure a Custom URL Category List Custom Object as follows (see URL White List for overview information).

  1. Select Configure>CLI Tools>Point and Click CLI.
  2. Next to Security, click Edit.
  3. Next to Utm, click Configure.
  4. Next to Custom objects, click Configure.
  5. Next to Custom url category, click Add new entry.
  6. Next to Name, enter a unique name for the list you are creating.
  7. Next to Value, click Add new entry.
  8. Next to Value, enter the name of the Url pattern list you created for bypassing scanning.
  9. Click OK. See Figure 128.

    Figure 128: Custom Object, Custom URL Category Configuration, Point and Click CLI Configuration

    Image ve_custom_url.gif

Now that your custom objects have been created, you can configure the antivirus feature profile.

  1. Select Configure>CLI Tools>Point and Click CLI.
  2. Next to Security, click Edit.
  3. Next to Utm, click Configure.
  4. Next to Feature profile, click Configure.
  5. Next to Anti virus, click Configure.
  6. Next to Juniper express engine, click Configure.
  7. Next to Pattern update, select the Yes check box and click Edit to set the interval.
  8. Next to Admin email, enter the e-mail addresses of the administrators who should receive e-mail notifications when updates are made to the pattern file.
  9. Next to Custom message, enter the text to appear in the body of the notification e-mail.
  10. Next to Custom message subject, enter the text to appear in the subject line of the notification e-mail. (The limit is 255 characters.)
  11. Next to Interval, enter the time interval for automatically updating the pattern database in the box. The default interval is 60. See Updating Antivirus Patterns for more information.
  12. Next to No autoupdate, select the No checkbox if you want to disable automatic updates and update the pattern database manually.
  13. Next to URL, if it is not already entered, enter the URL for the pattern database in the box. Note that the URL is http://update.juniper-updates.net/AV/<device version> and you should not change it.
  14. Click OK.
  15. Next to Profile, click Add new entry to create a profile for the Juniper Express Engine.
  16. Next to Name, enter a unique name for the profile you are creating.
  17. Next to Fallback options, select the Yes check box and click Edit to configure.
  18. Click OK.
  19. Next to Notification options, select the Yes check box and click Configure or Edit.
  20. Next to Scan options, select the Yes check box and click Configure or Edit.
  21. Next to Trickling, select the Yes check box and click Configure or Edit.
  22. Click OK.
  23. Click OK again to save the Juniper express engine profile.
  24. Back on the main Anti virus page, next to Mime whitelist, select the Yes check box and click Configure or Edit.
  25. Next to Name, enter the name of the Mime list custom object you created.
  26. Click OK.
  27. Next to Type, select juniper-express-engine from the list.
  28. Next to Url whitelist, enter the name of the URL whitelist custom object you created.
  29. Click OK. See Figure 129 for the Juniper express engine profile main window.

    Figure 129: Antivirus Express Profile, Point and Click CLI Configuration

    Image ve_exp_av_profile.gif

Next, you configure a UTM policy for express antivirus to which you attach the Juniper express engine profile you have configured.

  1. Select Configure>CLI Tools>Point and Click CLI.
  2. Next to Security, click Configure or Edit.
  3. Next to Utm, click Configure.
  4. Next to Utm policy, click Add new entry.
  5. In the Name box, enter a unique name for the UTM policy you are creating.
  6. Next to Anti virus, click Configure.
  7. In the Http, Imap, Pop3, or Smtp profile boxes, enter the name of the profile you created earlier. For Ftp, click Configure or Edit to enter Upload and Download profiles.

    Note: You create a separate antivirus profile for each antivirus protocol. These profiles may basically contain the same configuration information, but when you are creating your UTM policy for an antivirus profile, the UTM antivirus policy configuration page provides separate antivirus profile selection fields for each supported protocol.

  8. Click OK.
  9. Click OK again to return to main UTM configuration page. Your UTM antivirus policy is now listed in the UTM policy table.

Next, you attach the UTM policy to a security policy that you create.

  1. Select Configure>CLI Tools>Point and Click CLI.
  2. Next to Security, click Configure or Edit.
  3. Next to Utm, click Configure.
  4. Next to Policy, select the Yes check box click Edit.
  5. Next to Policy, click Add new entry.

    Note: Refer to the section on security policy configuration for further details on configuring a policy. Note that when you configure the Then field as part of the policy, select Permit as the action, and then configure Application services, you are able to enter the Utm policy name as part of this security policy.

  6. Next to Utm policy (in the Application services security policy window), enter the name of the appropriate policy. This attaches your UTM policy to the security policy.
  7. Click OK.

CLI Configuration

To configure antivirus protection using the CLI, you must first create your custom objects.

  1. Configure MIME lists. This includes creating a MIME whitelist and a MIME exception list for antivirus scanning. First create names for MIME lists and then add values to the lists. See MIME White List for overview information on MIME white lists.
    user@host# set security utm custom-objects mime-pattern avmime2
    user@host# set security utm custom-objects mime-pattern ex-avmime2
  2. Add MIME patterns to the lists.
    user@host# set security utm custom-objects mime-pattern avmime2 value [video/quicktime image/x-portable-anymap x-world/x-vrml]
    user@host# set security utm custom-objects mime-pattern ex-avmime2 value [video/quicktime-inappropriate]

Configure URL white lists for a list of URLs or addresses in a specified list that you want to be bypassed by antivirus scanning. First create names for the URL list and then add values to the list. See URL White List for overview information on URL white lists.

  1. Configure a URL pattern list custom object by creating the list name and adding values to it as follows:

    Note: Because you use URL pattern lists to create custom URL category lists, you must configure URL pattern list custom objects before you configure custom URL category lists.

    user@host# set security utm custom-objects url-pattern urllist2 value [http://www.juniper.net 1.2.3.4]

    Note: URL pattern wildcard support—The wildcard rule is as follows: \*\.[]\?* and you must precede all wildcard URLs with http://. You can only use “*” if it is at the beginning of the URL and is followed by a “.”. You can only use “?” at the end of the URL.

    The following wildcard syntax IS supported: http://*.juniper.net, http://www.juniper.ne?, http://www.juniper.n??. The following wildcard syntax is NOT supported: *.juniper.net , www.juniper.ne?, http://*juniper.net, http://*.

  2. Configure a custom URL category list custom object by using the URL pattern list you created as follows:
    user@host# set security utm custom-objects custom-url-category custurl2 value urllist2
  1. Now that your custom objects have been created, you can configure the antivirus feature profile. First, select and configure the engine type. Because you are configuring express antivirus, you select the juniper-express-engine.
    user@host# set security utm feature-profile anti-virus juniper-express-engine
  2. Select a time interval for updating the pattern database. The default antivirus pattern-update interval is once a day. You can choose to leave this default as is or you can change it. You can also force a manual update, if necessary. See Updating Antivirus Patterns for more information.
    user@host# set security utm feature-profile anti-virus juniper-express-engine pattern-update interval 12
  3. The command for changing the URL for the pattern database is:
    user@host# set security utm feature-profile anti-virus juniper-express-engine pattern-update urlhttp://...

    Note: Under most circumstances, you should not need to change the default URL.

  4. You can configure the device to notify a specified administrator when patterns are updated. This is an e-mail notification with a custom message and a custom subject line.
    user@host# set security utm feature-profile anti-virus juniper-express-engine pattern-update email-notify admin-email administrator@juniper.net custom-message “pattern file was updated” custom-message-subject “AV pattern file updated”
  5. Configure a profile for the Juniper-Express-Engine. This profile includes configuring fallback, notification, and scanning options. It also includes HTTP trickling configuration options. First, you create the profile name.
    user@host# set security utm feature-profile anti-virus juniper-express-engine profile junexprof1
  6. Configure a list of fallback options as “block” or “log and permit.” In most cases, the default is to block. You can use the default settings or you can change them. See Fallback Options for a detailed overview of this feature and each fallback category.
    user@host# set security utm feature-profile anti-virus juniper-express-engine junexprof1 fallback-options content-size block
    user@host# set security utm feature-profile anti-virus juniper-express-engine jjunexprof1 fallback-options default block
    user@host# set security utm feature-profile anti-virus juniper-express-engine junexprof1 fallback-options engine-not-ready block
    user@host# set security utm feature-profile anti-virus juniper-express-engine junexprof1 fallback-options out-of-resources block
    user@host# set security utm feature-profile anti-virus juniper-express-engine junexprof1 fallback-options timeout block
    user@host# set security utm feature-profile anti-virus juniper-express-engine junexprof1 fallback-options too-many-requests block
  7. Configure the notification options. You can configure notifications for both fallback blocking and fallback nonblocking actions and for virus detection. See Understanding Virus-Detected Notification Options for overview information on notification options.

    In this step, configure a custom message for the fallback blocking action and send a notification. See Custom Message Notification for overview information.

    user@host# set security utm feature-profile anti-virus juniper-express-engine jjunexprof1 notification-options fallback-block custom-message ***virus-found*** notify-mail-sender
  8. Configure a notification for protocol-only virus detection and send a notification. See Protocol-Only Notifications for overview information.
    user@host# set security utm feature-profile anti-virus juniper-express-engine junexprof1 notification-options virus-detection type protocol-only notify-mail-sender
  9. You can also configure a custom subject line for the custom message notification for both the sender and the recipient.
    user@host# set security utm feature-profile anti-virus juniper-express-engine jjunexprof1 notification-options fallback-block custom-message-subject “Antivirus Alert” notify-mail-sender
  10. Configure content size parameters. The content size check occurs before the scan request is sent. The content size refers to accumulated TCP payload size. See Content Size Limits for details.
    user@host# set security utm feature-profile anti-virus juniper-express-engine junexprof1 scan-options content-size-limit 20000
  11. Configure intelligent prescreening. It is either on or off. See Intelligent Prescreening for details. (Intelligent prescreening is only intended for use with non-encoded traffic. It is not applicable for mail protocols (SMTP, POP3, IMAP) and HTTP POST.)
    user@host# set security utm feature-profile anti-virus juniper-express-engine junexprof1 scan-options intelligent-prescreening
    user@host# set security utm feature-profile anti-virus juniper-express-engine junexprof1 scan-options no-intelligent-prescreening
  12. Configure the time-out setting. See Scanning Timeout for overview details.
    user@host# set security utm feature-profile anti-virus juniper-express-engine junexprof1 scan-options timeout 1800
  13. Configure trickling settings. If you use trickling, you can also set timeout parameters. Trickling applies only to HTTP. HTTP trickling is a mechanism used to prevent the HTTP client or server from timing out during a file transfer or during antivirus scanning. See HTTP Trickling for overview details.
    user@host# set security utm feature-profile anti-virus juniper-express-engine junexprof1 trickling timeout 600
  14. Configure the antivirus module to use MIME bypass lists and exception lists. You can use your own custom object lists or you can use the default list that ships with the device called “junos-default-bypass-mime.” See MIME White List for overview information.)
    user@host# set security utm feature-profile anti-virus mime-whitelist list avmime2
    user@host# set security utm feature-profile anti-virus mime-whitelist list avmime2 exceptionex-avmime2
  15. Configure the antivirus module to use URL bypass lists. If you are using a URL white list, this is a custom URL category you have previously configured as a custom object. URL white lists are only valid for HTTP traffic. See URL White List for overview information.)
    user@host# set security utm feature-profile anti-virus url-whitelist custurl2
  1. Configure a UTM policy for an antivirus scanning protocol and attach this policy to a profile. See Global, Profile-Based, and Policy-Based Scan Settings for information on policy and profile-based scanning.

    CLI commands for configuring a UTM policy for HTTP antivirus scanning and attaching that policy to a profile we created earlier for antivirus scanning are:

    user@host# set security utm utm-policy <name>
    user@host# set security utm utm-policy utmp3 anti-virus http-profile junexprof1
  2. Attach the UTM policy to a firewall security policy.
    user@host# set security policies from-zone trust to-zone untrust policy p3 match source-address any
    user@host# set security policies from-zone trust to-zone untrust policy p3 match destination-address any
    user@host# set security policies from-zone trust to-zone untrust policy p3 match application junos-http
    user@host# set security policies from-zone trust to-zone untrust policy p3 then permit application-services utm-policy utmp3

Note: For information on Express Antivirus Notifications and Verification, refer toUnderstanding Virus-Detected Notification Options, and Verifying Antivirus Configurations.


[ Contents] [ Prev] [ Next] [ Index] [ Report an Error]