Announcement Banner
UNSOLVED

nasgurunot

updated

19 years ago

N

nasgurunot

29 Posts

0

837

August 9th, 2007 08:00

virus scanning

My environment has a virus engine McAffee running against all windows. So, when a cifs share is accessible on the windows by all users, if a user drops an infected file on the cifs share, does McAffee server catch that? What exactly is the CAVA and would I need that for my environment?
  • nandas

    6 Operator

    •

    1473 Posts

    298

    1

    Posted August 9th, 2007 09:00

    If the user has real-time scanning enabled on his/her desktop, then the virus will be caught on the desktop itself - it will not go to the NAS share.

    CAVA is a virus solution for EMC NAS boxes - but CAVA does not do any scanning on its own - it is an agent to interface the NAS with the AV server in the network. All the scanning will be done by your AntiVirus Server (having the scan engine - depends on what vendor you use). The CAVA client will be installed on the AV Server which runs as a service on the AV server. You need to do some more configuration on the AV Server, based on the product that you ar eusing.

    On the NAS - you configure the virus scanning configuration file where you mention the IP Address of the AV Servers and start the virus scanning service. Also you choose all scanning policy (like file types to be scanned etc - you can do these through MMC tool).

    So, when any user writes on the NAS share, since virus scanning is enabled on the NAS and it knows the AV servers, the header information of the file is sent to AV server for virus scanning and once no threat is found, the write operation is complete. If any threat is detected, it either deletes the file or take other action based on the AV server configuration.

    Please note, this scanning is done on the Network and it is very important to build the list of file types you want to scan - or to build the exclusion list if you select to scan all files with some exclusion.

    It may a good idea to have a dedicated network interface on NAS for virus scanning. You also need to have a dedicated domain user for this purpose, the user will have local admin right on AV server and will be assigned special permission for virus scanning on the Celerra (you may use MMC tool for this as well).

    Lastly - if you are absolutely sure that, there will be no client/machine on your network which will not have real time virus scanning, then CAVA scanning will be a duplicate effort. But many times, user may stop virus scanning on their machine - or any new machine is on the network with no Antivirus software etc etc - which justifies the use of CAVA with the NAS box.

    Hope this helps. Please let me know, if any more information is required. Please refer to EMC Document "Using CAVA" for more information.

    Thanks,
    Sandip
  • nandas

    6 Operator

    •

    1473 Posts

    298

    0

    Posted August 13th, 2007 09:00

    Hi,

    I hope you are doing much better - please let me know, if you need any more details.

    Thanks,
    Sandip
  • Rainer_EMC

    6 Operator

    •

    8645 Posts

    298

    1

    Posted August 13th, 2007 10:00

    a couple of things to remember when implementing CAVA with Celerra

    - CAVA (the interface software between Celerra and AV server) is a licensed product based on the number of AV servers so you need to look if you bought it with your Celerra

    - check the EMC support matrix or the CAVA release notes which AV vendor's products and versions are supported

    - for Mcafee it is currently VSE 8.0 ( 8.5i currendly has some issues expected to be fixed when the next patch3 comes out )
  • nasgurunot

    29 Posts

    298

    0

    Posted August 13th, 2007 12:00

    Your information was indeed helpful. Thanks much.
  • nasgurunot

    29 Posts

    298

    0

    Posted August 13th, 2007 12:00

    Thanks. All the info helped.