OPNsense
  • Home
  • Help
  • Search
  • Login
  • Register

  • OPNsense Forum »
  • English Forums »
  • Web Proxy Filtering and Caching (Moderator: fabian) »
  • Clamav + c-icap, but I can download the virus.
« previous next »
  • Print
Pages: [1]

Author Topic: Clamav + c-icap, but I can download the virus.  (Read 3133 times)

WhiteTiger

  • Jr. Member
  • **
  • Posts: 73
  • Karma: 1
    • View Profile
Clamav + c-icap, but I can download the virus.
« on: June 21, 2020, 06:02:31 pm »
I am new to OPNSense and I am activating the different services by following the documentation step by step.
I installed and configured clamav and c-icap, but then when I download eicar.com this arrives on my PC while I expected it to be blocked by the AV.
Nor do I see reports  somewhere in the GUI.
Where am I wrong?
In the Lobby/Dashport clamav is active and in the clamav configuration the freshclam service is enabled, but I don't see signatures in the tab.
What checks should I make to make sure everything is working properly?

Logged

mimugmail

  • Hero Member
  • *****
  • Posts: 6767
  • Karma: 494
    • View Profile
Re: Clamav + c-icap, but I can download the virus.
« Reply #1 on: June 21, 2020, 08:01:38 pm »
Your browser forces HTTPS which you need to break whem you want to scan it
Logged
WWW: www.routerperformance.net
Support plans: https://www.max-it.de/en/it-services/opnsense/
Commercial Plugins (German): https://opnsense.max-it.de/

WhiteTiger

  • Jr. Member
  • **
  • Posts: 73
  • Karma: 1
    • View Profile
Re: Clamav + c-icap, but I can download the virus.
« Reply #2 on: June 22, 2020, 10:14:38 am »
Quote from: mimugmail on June 21, 2020, 08:01:38 pm
Your browser forces HTTPS which you need to break whem you want to scan it
By now all browsers force the https connection.
I did not understand what I have to do.
I want if someone downloads a file with a virus, or is blocked or in any case reported.
Logged

franco

  • Administrator
  • Hero Member
  • *****
  • Posts: 17751
  • Karma: 1620
    • View Profile
Re: Clamav + c-icap, but I can download the virus.
« Reply #3 on: June 22, 2020, 12:19:08 pm »
You will have to properly proxy HTTPS in order for this to work.


Cheers,
Franco
Logged

mimugmail

  • Hero Member
  • *****
  • Posts: 6767
  • Karma: 494
    • View Profile
Re: Clamav + c-icap, but I can download the virus.
« Reply #4 on: June 22, 2020, 03:19:06 pm »
https://docs.opnsense.org/manual/proxy.html#setup-transparent-mode-including-ssl


You cant scan encrypted traffic if you don't break it
Logged
WWW: www.routerperformance.net
Support plans: https://www.max-it.de/en/it-services/opnsense/
Commercial Plugins (German): https://opnsense.max-it.de/

WhiteTiger

  • Jr. Member
  • **
  • Posts: 73
  • Karma: 1
    • View Profile
Re: Clamav + c-icap, but I can download the virus.
« Reply #5 on: June 22, 2020, 04:16:45 pm »
Quote from: mimugmail on June 22, 2020, 03:19:06 pm
https://docs.opnsense.org/manual/proxy.html#setup-transparent-mode-including-ssl


You cant scan encrypted traffic if you don't break it
I had already read that page where, however, it is also written that it is not convenient to enable it if you request access to HTTPS sites such as those of banks.
At least I have interpreted it this way and therefore I have not enabled the transparent on HTTPS.
Logged

fabian

  • Moderator
  • Hero Member
  • *****
  • Posts: 2769
  • Karma: 200
  • OPNsense Contributor (Language, VPN, Proxy, etc.)
    • View Profile
    • Personal Homepage
Re: Clamav + c-icap, but I can download the virus.
« Reply #6 on: June 22, 2020, 05:43:53 pm »
You can exclude some sites where you don't want the proxy to intercept. For example online banking and domains where it might be prohibited such as email services.
Logged

  • Print
Pages: [1]
« previous next »
  • OPNsense Forum »
  • English Forums »
  • Web Proxy Filtering and Caching (Moderator: fabian) »
  • Clamav + c-icap, but I can download the virus.
 

OPNsense is an OSS project © Deciso B.V. 2015 - 2024 All rights reserved
  • SMF 2.0.19 | SMF © 2021, Simple Machines
    Privacy Policy
    | XHTML | RSS | WAP2