Prerequisites |
Make sure ClamAV is properly installed and XWall can communicate native with the ClamAV service |
SaneSecurity Rules |
You have two options to download the rules: Either using the old ClamSup, which has more options, or using the new Sigupdate, which is simpler to install. Using ClamSup (this no longer works, because the download links are invalid) Download ClamSup.zip Note: You need to open port 873 in the firewall to make cwRsync working. Create a directory named ClamSup beside the ClamAV directory e.g. assuming that ClamAV is in C:\ClamAV then create C:\ClamSup Extract the downloaded files into the ClamSup directory Open ClamSup.cfg with an editor and adjust the path so that it matches your ClamAV installation Make sure the line LOCALFOLDER=C:\ClamAV\db points to the db folder in the ClamAV directory. Open a DOS Box, change to the ClamSup directory and type start ClamSup.bat -v ClamSup will run for a few minutes and download all SaneSecurity databases. After the download ClamSup copies the databases into the ClamAV db folder and restarts ClamAV. In the case ClamSup.bat immediately closes, locate clamsup.error and check the error. Once you fixed the error, start ClamSup.bat again. Create a schedule that starts ClamSup.bat every 2 hours Using Sigupdate From http://sanesecurity.com/usage/windows-scripts/ download ClamWin/ClamAV Sigupdate 0.4 beta Note: You need to open port 873 in the firewall to make cwRsync working. Create a directory named Sigupdate beside the ClamAV directory e.g. assuming that ClamAV is in C:\ClamAV then create C:\Sigupdate Extract the downloaded files into the Sigupdate directory Download Rsync for Windows Note: You need to open port 873 in the firewall to make cwRsync working. Extract the file in the bin directory into the Sigupdate\winrsync directory Open Sigupdate.bat with an editor and adjust the path so that it matches your ClamAV installation Open a DOS Box, change to the ClamSup directory and type Sigupdate.bat Sigupdate will run for a few seconds and download all SaneSecurity databases. After the download Sigupdate copies the databases into the ClamAV db folder and restarts ClamAV. Create a schedule that starts Sigupdate.bat every 2 hours In XWall enable Options->Spam->SaneSecurity and send a test message. |
ClamAV Configuration |
Suggested settings for ClamAV in clamd.conf: |
Testing SaneSecurity |
Save the following message into a file and send the file using SMTPSend and the -g option to XWall. SaneSecurity should detect the special subject as a test message. For more information on signature testing see http://sanesecurity.com/support/signature-testing/ _Begin of SaneSecurity test message_ |