Re: how can a firewall box handle virus?



On Nov 13, 6:17 am, "peter" <nos...@xxxxxxxxxx> wrote:
Some new firewall boxes advertised DPI and virus protection (e.g. sonicwall
tz180). Sounds attractive. But how does it work?

Let's say I'm downloading a pop3 email. Does the firewall stores the entire
email and attachment, scan it for virus, then forward it on if it's clean?

No. It just inspects it while it is downloading just like any other
antivirus software does. They start at the beginning and end at the
end. You only need a small buffer for that.

But it also does not work miracles. It does not forward anything "if
it's clean". It only recognizes for what it has signatures. It won't
recognize the newest malware until the signatures have it. It won't
recognize very rare malware. It will also recognize things which are
not bad. It will also recognize malware which is actually not
dangerous on your computer because your computer is not vulnerable.

So basically, it may find a few things but it is still and always you
who has to decide what's clean or not.

Gerald

.



Relevant Pages

  • Re: Total Security Trojan
    ... I use that email only for newsgroups to capture spam messages which I then use to update my hosts file and Remove-it definitions. ... >>> I recommend downloading and installing MalwareBytes' Antimalware ... >> saving security monitor detected this or that. ... >> by the frequent interruptions caused by the malware. ...
    (microsoft.public.windowsxp.basics)
  • Re: Total Security Trojan
    ... Reboot ... along with an app download option; ... wary of downloading anything unknown ... by the frequent interruptions caused by the malware. ...
    (microsoft.public.windowsxp.basics)
  • Spam trojan that actually downloads and runs AV software (!)
    ... SpamThru attempts to prevent ... installed anti-virus software from downloading updates by ... we've also seen malware which tries to uproot ... requests and loads a DLL from the control server. ...
    (alt.comp.anti-virus)
  • Re: Total Security Trojan
    ... I was unable to open task manager, ... along with an app download option; ... wary of downloading anything unknown ... by the frequent interruptions caused by the malware. ...
    (microsoft.public.windowsxp.basics)
  • Re: ise32 Properties
    ... I did the reinstallation twice and the thumbdrive was clean. ... The copy of Vista SP 1 was downloaded using another computer. ... I searched online and found out that this is a virus. ... downloading something else that you haven't mentioned. ...
    (microsoft.public.windows.vista.installation_setup)