Symantec 360R Administration Guide - Page 108

Firewall, Enable Antivirus Policy, Enforcement, Warn Only, Block Connections

Page 108 highlights

108 Advanced network traffic control Configuring AVpe To enable AVpe After you have configured AVpe, you must enable it for each computer or VPN group. Note: Enabling AVpe for VPN groups is for WAN clients only. You enable AVpe for LAN VPN clients through Computer groups in the Firewall section. See "Defining computer group membership" on page 65. See "Defining client VPN tunnels" on page 99. See "Computer Groups tab field descriptions" on page 179. See "Client Tunnels tab field descriptions" on page 197. To enable antivirus policy enforcement for computer groups 1 In the SGMI, in the left pane, click Firewall. 2 On the Computer Groups tab, under Security Policy, on the Computer Group drop-down list, select the computer group for which you want to enable AVpe. 3 Under Antivirus Policy Enforcement, check Enable Antivirus Policy Enforcement, and then do one of the following: ■ To log warnings for clients with out-of-date virus definitions, click Warn Only. ■ To completely block connections from clients with out-of-date virus definitions, click Block Connections. 4 Click Save. 5 Repeat steps 2 through 6 to enable AVpe for each computer group. To enable antivirus policy enforcement for VPN groups 1 In the left pane of the Security Gateway Management Interface (SGMI), click VPN. 2 On the Client Tunnels tab, under Group Tunnel Definition, on the VPN Group drop-down list, select the VPN group for which you want to enable AVpe. 3 Under WAN Client Policy, check Enable Antivirus Policy Enforcement, and then do one of the following: ■ To log warnings for clients with out-of-date virus definitions, click Warn Only. ■ To completely block connections from clients with out-of-date virus definitions, click Block Connections.

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218

108
Advanced network traffic control
Configuring AVpe
To enable AVpe
After you have configured AVpe, you must enable it for each computer or VPN
group.
Note:
Enabling AVpe for VPN groups is for WAN clients only. You enable AVpe
for LAN VPN clients through Computer groups in the Firewall section.
See
“Defining computer group membership”
on page 65. See
“Defining client
VPN tunnels”
on page 99.
See
“Computer Groups tab field descriptions”
on page 179.
See
“Client Tunnels tab field descriptions”
on page 197.
To enable antivirus policy enforcement for computer groups
1
In the SGMI, in the left pane, click
Firewall
.
2
On the Computer Groups tab, under Security Policy, on the Computer Group
drop-down list, select the computer group for which you want to enable
AVpe.
3
Under Antivirus Policy Enforcement, check
Enable Antivirus Policy
Enforcement
, and then do one of the following:
To log warnings for clients with out-of-date virus definitions, click
Warn Only
.
To completely block connections from clients with out-of-date virus
definitions, click
Block Connections
.
4
Click
Save
.
5
Repeat steps 2 through 6 to enable AVpe for each computer group.
To enable antivirus policy enforcement for VPN groups
1
In the left pane of the Security Gateway Management Interface (SGMI), click
VPN
.
2
On the Client Tunnels tab, under Group Tunnel Definition, on the VPN
Group drop-down list, select the VPN group for which you want to enable
AVpe.
3
Under WAN Client Policy, check
Enable Antivirus Policy Enforcement
, and
then do one of the following:
To log warnings for clients with out-of-date virus definitions, click
Warn Only
.
To completely block connections from clients with out-of-date virus
definitions, click
Block Connections
.