Anti-Virus

The Anti-Virus security engine scans network traffic and prevents the download of malicious files from the internet, while also blocking access to malicious and phishing websites.

Kaspersky NGFW controls TCP traffic transmitted over the following protocols, including encrypted versions:

To control encrypted traffic, you need to enable encrypted connection scanning. Traffic transmitted via other protocols is not scanned by Anti-Virus

The scan is performed using the following components:

For the Anti-Virus security profile, you can enable one or more traffic scanning components. The components scan traffic in the following order:

  1. URL scanning module
  2. Object Anti-Virus
  3. Stream Anti-Virus

The action selected in the Anti-Virus security profile is performed if at least one of the components included in the security profile detects malware in traffic or if an URL fails the reputation check.

In the default Anti-Virus profile, the Stream Anti-Virus and URL reputation checking are enabled and use the local database. Local Anti-Virus databases are updated automatically as part of the general update task.

When an attempt is made to download a malicious object or visit a compromised website, Kaspersky NGFW blocks access and, if you have selected the corresponding action, displays a warning page telling the user about the block and offering further instructions.

In this section

Table of Anti-Virus profiles

Creating an Anti-Virus profile

Editing an Anti-Virus profile

Deleting an Anti-Virus profile

Anti-Virus scanning of archive contents

Filtering files in network traffic

Page top