Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Howard_Gyton
Advisor

SCV - Canonical list of supported/detectable anti-virus clients

We've recently been looking at tightening up our SCV policy for BYOD devices running the standalone VPN client.

Looking over the R81 Remote Access VPN Administration Guide, there is mention of some clients that are supported, but it differs depending on which section you look at.

For example, at the top of the section "Secure Configuration Verification - Advanced", it mentions this:

  • Anti-Virus Monitor - Verifies that an Anti-Virus is running and checks its version. Supported: Norton, Trend Office Scan, and McAfee.

But when you expand the Anti-Virus monitor section, it mentions this:

Type ("av_type")

Type of Anti-Virus. For example, "Norton", "VirusScan", "McAfee", "OfficeScan", or "ZoneLabs".

 

In the "local.scv" file itself this is obviously a free text field, but how free?  How would we detect "Windows Defender" on a Windows machine, for example, and is that even possible?

Howard

0 Kudos
1 Reply
PhoneBoy
Admin
Admin

This AV check predates what is probably the better way to achieve this: using  WindowsSecurityMonitor https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_RemoteAccessVPN_AdminGuide/C... 
With this, you can use any AV that Microsoft detects, which I assume would also include Defender 🙂
The procedure for finding the exact name to use in SCV is here: https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_RemoteAccessVPN_AdminGuide/C... 

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events