Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Scott_Paisley
Advisor
Jump to solution

Anti-virus signature not found

We have logs indicating an anti-virus signature detected something, but didn't prevent it.

I want to change the action to drop, but I can't find the signature

What am I doing wrong?

0 Kudos
1 Solution

Accepted Solutions
Timothy_Hall
Champion Champion
Champion

Was starting to suspect this was a cloud-based detection of something new for which no signature had been propagated yet, but as it turns out you can't find it in the SmartConsole now because it has been removed in an update, from the ThreatWiki: 

gone.png 

 

Gateway Performance Optimization R81.20 Course
now available at maxpowerfirewalls.com

View solution in original post

8 Replies
Timothy_Hall
Champion Champion
Champion

Need to see the full log card for this log entry with IP addresses redacted.

Gateway Performance Optimization R81.20 Course
now available at maxpowerfirewalls.com
0 Kudos
Scott_Paisley
Advisor

attached

0 Kudos
Timothy_Hall
Champion Champion
Champion

Please fully expose (with redaction as needed) all areas of the log card that have a caret "^" pointing downwards.  Can't even tell if it is Anti-bot or Anti-virus with that screenshot.

Gateway Performance Optimization R81.20 Course
now available at maxpowerfirewalls.com
0 Kudos
Scott_Paisley
Advisor

anti-virus

0 Kudos
G_W_Albrecht
Legend
Legend

I would suggest to change all detect to prevent - its the same resources spent but no action taken (except a log) with detect.

But better contact TAC about this...

CCSE CCTE CCSM SMB Specialist
0 Kudos
Scott_Paisley
Advisor

that's what I want to do, but I can't find the protection to make that change

0 Kudos
Timothy_Hall
Champion Champion
Champion

Was starting to suspect this was a cloud-based detection of something new for which no signature had been propagated yet, but as it turns out you can't find it in the SmartConsole now because it has been removed in an update, from the ThreatWiki: 

gone.png 

 

Gateway Performance Optimization R81.20 Course
now available at maxpowerfirewalls.com
Scott_Paisley
Advisor

OK, thanks

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events