Old 04-11-2010, 05:38 PM   #11 (permalink)
Untangle Ninja
 
YeOldeStonecat's Avatar
 
Join Date: Aug 2007
Posts: 1,394
YeOldeStonecat is on a distinguished road
Default

Quote:
Originally Posted by hescominsoon View Post
that's interesting you say that. It consistently has detection rates that will compete with anything. It is NOT an real-time scanner on a pc..it is an on demand scanner like in the case of a mail scanner. Use it as it is designed..as an on demand type scanner and it will hang with anything. I have never seen it miss anything AND unlike the commercial big boys it's NEVER had a false positive.
I'm not going to get into a debate about the effectiveness of Clam...most of us in IT have seen reviews of it over the years showing its performance. It does "OK" as an SMTP scanner, yes. And yes I'm more than very well aware that it doesn't have real time file protection.

Back to my point...I was puzzled as to why a far superior product, KAV, wasn't racking up a score in its module. It' still all zeros. We move over 1500 mails though our UT box per day, and with the AV module bagging from 20-30 per day on average, since I'm sure we can all agree that no AV product gets 100% of all infections...even the best muster in the upper 90% range..by now a few should have slipped by. I'm confident anyone worth their salt who's been in IT for an appreciable period of time would support that KAV is superior. Hence my question.
YeOldeStonecat is offline  
Old 04-11-2010, 05:44 PM   #12 (permalink)
Untangle Ninja
 
sky-knight's Avatar
 
Join Date: Apr 2008
Location: Phoenix, AZ
URLs submitted: 8
Posts: 15,464
sky-knight is on a distinguished road
Default

KAV is in a slump? There's always that ebb and flow of general effectiveness in these things... That's why we have two in there.
__________________
Rob Sandling, BS:SWE, MCP
Intouch Technology
Phone: 480-272-9889
rob@intouchtechllc.com

UntangleAppliances.com
Phone: 866-794-8879
sky-knight is offline  
Old 04-11-2010, 06:59 PM   #13 (permalink)
Untangle Ninja
 
hescominsoon's Avatar
 
Join Date: Sep 2007
URLs submitted: 2
Posts: 1,427
hescominsoon is on a distinguished road
Default

Quote:
Originally Posted by YeOldeStonecat View Post
I'm not going to get into a debate about the effectiveness of Clam...most of us in IT have seen reviews of it over the years showing its performance. It does "OK" as an SMTP scanner, yes. And yes I'm more than very well aware that it doesn't have real time file protection.

Back to my point...I was puzzled as to why a far superior product, KAV, wasn't racking up a score in its module. It' still all zeros. We move over 1500 mails though our UT box per day, and with the AV module bagging from 20-30 per day on average, since I'm sure we can all agree that no AV product gets 100% of all infections...even the best muster in the upper 90% range..by now a few should have slipped by. I'm confident anyone worth their salt who's been in IT for an appreciable period of time would support that KAV is superior. Hence my question.
I don't think KAV is truly superior to be honest..you can take your opinion of if i am worth my salt or not. The reason Kav hasn't caught anything is nothing got by clam. If you run a/v on your desktops check them and see if anything in e-mail has gotten by UT..
__________________
Multi-vendor Firewall Reseller
Registered Microsoft Partner
Emmanuel Computer Consulting, L.L.C.
http://www.eccmd.com
hescominsoon is offline  
Old 04-23-2010, 07:18 PM   #14 (permalink)
Untangler
 
Join Date: Oct 2008
Location: Vancouver, WA
Posts: 80
redhale3 is on a distinguished road
Default

It's interesting that, after having this discussion, one day this week one of my client's UT blocked a burst of files. KAV blocked 14 and Clam blocked 5. On the same machine I noticed that today KAV blocked 4 and Clam blocked 3. I guess it does make sense to have them both.
redhale3 is offline  
Old 04-24-2010, 06:29 AM   #15 (permalink)
Master Untangler
 
Join Date: Aug 2008
URLs submitted: 2
Posts: 442
Danp is on a distinguished road
Default

KAV also blocked 1 virus for me this week. Actually, I just checked and its up to 2! Both are DHL related email viruses.

The interesting thing is that KAV appears to be scanning before Clam. The attached image shows that KAV has scanned two more documents than Clam, which makes sense if KAV has blocked two.

FWIW, I've also seen entries in the KAV log where it passed stuff like the UPS email viruses that were then blocked by Clam.
Attached Images
File Type: jpg 0002.JPG (33.0 KB, 15 views)
Danp is online now  
Old 05-17-2010, 10:43 AM   #16 (permalink)
Master Untangler
 
neiby's Avatar
 
Join Date: Jun 2009
Location: Denver, CO
Posts: 603
neiby is on a distinguished road
Default

We've been running KAV for months and I don't think it's ever blocked a virus. It notices the EICAR test file, but I don't recall ever seeing the blocked counter go up when I wasn't testing with EICAR. I just enabled Clam to see if there is something weird going on.
__________________
Disclaimer: I may or may not have had enough coffee when I'm posting. Interpret my responses thusly.
neiby is offline  
Old 06-19-2010, 01:40 PM   #17 (permalink)
Newbie
 
Join Date: Apr 2010
Posts: 4
LR897 is on a distinguished road
Default

Quote:
Originally Posted by Danp View Post
KAV also blocked 1 virus for me this week. Actually, I just checked and its up to 2! Both are DHL related email viruses.

The interesting thing is that KAV appears to be scanning before Clam. The attached image shows that KAV has scanned two more documents than Clam, which makes sense if KAV has blocked two.

FWIW, I've also seen entries in the KAV log where it passed stuff like the UPS email viruses that were then blocked by Clam.
I checked on the Untangle wiki and is says that Kaspersky scans first before ClamAV.

" If I have both virus blockers installed, are one or both used and in which order?

If you have only one virus blocker installed then only that scanner will be applied, according to the settings you have established, assuming the Rack element is powered up. If you have two virus scanners installed then the "for fee" service is applied to a message first: if a message passes the "for fee" scanner then and only then the open source scanner is applied to the message (there's no point in scanning the message twice if the first scanner has rejected it.) This is not to say one scanner is inherently better than the another: we point this out in the event you are evaluating the two scanners against one another to determine which or both best fits your needs. In this case, note that the "for fee" scanner is complemented by the open source scanner and in the case of a virus-free message, the computational overhead of the virus scan includes both scanners; where as a message that would be rejected by both scanners incurs the computational and time cost of just the "for fee" scanner. So, to perform a valid comparison, you should run test messages through the Untangle Gateway with no scanners installed, the "for fee" scanner by itself, the open source scanner by itself and lastly both scanners installed together and compare the results. "

I can't post links yet, so you will have to add the http to read the wiki:
://wiki.untangle.com/index.php/Virus_Blocker
LR897 is offline  
Old 06-19-2010, 02:27 PM   #18 (permalink)
Master Untangler
 
boyan.sharic's Avatar
 
Join Date: May 2009
Location: Banja Luka, Bosnia and Herzegovina
URLs submitted: 3
Posts: 111
boyan.sharic is on a distinguished road
Default

Quote:
Originally Posted by Danp View Post
KAV also blocked 1 virus for me this week. Actually, I just checked and its up to 2! Both are DHL related email viruses.

The interesting thing is that KAV appears to be scanning before Clam. The attached image shows that KAV has scanned two more documents than Clam, which makes sense if KAV has blocked two.

FWIW, I've also seen entries in the KAV log where it passed stuff like the UPS email viruses that were then blocked by Clam.
maybe file/MIME types that are being scanned are not the same on both of your modules
boyan.sharic is offline  
Closed Thread

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 10:25 AM.


© 2010 Untangle, Inc. All Rights Reserved.   SEO by vBSEO 3.6.0 PL2