You are welcome to subscribe to "New articles in Knowledge base" mailing list:

You are visiting our Support Website and we thank you in advance for your participation in this poll and your feedbacks.

Please vote honestly, we will analyze the results and will do our best to improve our service as soon as possible.

 Corporate Support Website Usability Survey:
Navigation quality*
Technical articles efficiency*
Relevance of the article(s) turned out by your query*
Ease of access to relevant information*
Comments

Read the same in:    English  Deutsch  日本語  Русский  
Home / Business products /  File server protection /  Microsoft Windows /  Kaspersky Anti-Virus 6.0 for Windows Servers Enterprise Edition MP2 (builds 6.0.2. [551-555]) /  Setting Real-time protection

 
Search :  
Search tips Article ID # :   
 

Kaspersky Anti-Virus 6.0 for Windows Servers Enterprise Edition MP2 (builds 6.0.2. [551-555])

 
How to block access to the server from infected computers in the network
 ID Article: 1622    Other languages:  Deutsch  日本語  Русский   Will be translated:  Polski     Views for 7 days 22    Last modified on 2008 Aug 14 10:36 Printable version

Concerning to Kaspersky Anti-Virus 6.0 for Windows Servers Enterprise Edition MP1/MP2

Kaspersky Anti-Virus 6.0 for Windows Servers Enterprise Edition has the option to block access to the protected server from infected computers in the network. It means, if an infected/ suspicious file is tried to be saved on the server from a specified computer of the network, then the Anti-Virus gives the computer the infected status and does not allow access to the server for the set period of time. It does not matter under which account the following attempts to connect with the protected server are made. Additionally when blocking computer an executable can be run on the server.

But if necessary the server administrator can unblock the computer ahead of schedule and grant it access to the server. The application also supports the possibility to create list of trusted computers which are never blocked.

Information If you add a computer which is being blocked at present to the list of trusted computers, this computer will be given access to the server only when the blocking period s over.

 

Blocking of infected computers automatically functions with the following conditions:

1. Blocking option should be enabled (by default the option is disabled).

2. Real-time file protection task should be running

3. Protection mode in the task Real-time file protection should be set on Smart mode or On access or modification.

Also if necessary the administrator can manually block specified computers.

If the number of blocked computers exceeds the set number (it means you have the virus outbreak in the logical network) Anti-Virus can start functioning with stricter security settings (the Real-time file protection task): 

  • protection modeOn access and modification
  • objects scannedby format 
  • productivity – the box Scan only new and changed files is cleared, 
  • actions to be performed on infected objectsDisinfect; delete if disinfection fails
  • actions to be performed on suspicious objects - Quarantine
  • process compound objects: 
    • All SFX archives 
    • All packed objects 
    • All embedded OLE-objects

Values of the parameters Archives, Mail databases and plain mail do not change.

Values of other parameters do not change.

When the virus activity diminishes together with the number of blocked computers Anti-Virus starts functioning with its previous working parameters. All changes applied to the Anti-Virus during the virus outbreak period, i.e. when it is running with stricter settings, will be ignored. These changes will be applied to the Anti-Virus later when it automatically returns to the previous settings.

All operations concerning blocking/ unblocking access from the computers and data about changes made in the Anti-Virus security parameters are registered in the system audit log.

The list of blocked computers is automatically saved between the Anti-Virus sessions. To view the list of blocked computers in the Anti-Virus Console click the Blocking access from computers node.

 

How to choose Protection mode in the Real-time file protection task?

Via the Anti-Virus Console:

1. Open the Anti-Virus Console and in the console tree choose Real-time protection

2. Right-click the Real-time file protection node and choose Properties

3. In the open window on the tab Protection mode set the necessary mode.

Via Kaspersky Administration Kit:

1. Open the policy for Kaspersky Anti-Virus 6.0 for Windows Servers Enterprise Edition; the policy should be active for the necessary protected server.

2. Go to the tab Real-time file protection and in the Protection mode section set the necessary mode.

 

3. “Lock” the settings for the settings to be applied on the protected server. Click the Apply button.

How to launch the task Real-time file protection?

Via the Anti-Virus Console:

1. Open the Anti-Virus Console and in the console tree choose Real-time protection.

2. Right-click the node Real-time file protection and choose the task Start task

3. Make sure Real-time file protection is running.

Via Kaspersky Administration Kit:

1. Open the properties of a client computer – protected server on the Tasks tab

2. In the list of tasks choose Real-time file protection and in the context menu choose Run.

How to enable and to set automatic blocking of computers and prevention of virus outbreaks?

Via the Anti-Virus Console:

1. Open the Anti-Virus Console and in the console tree choose Real-time protection.

2. Expand the node Real-time file protection > right-click the node Blocking access from computers and choose Properties.

3. In the open window: 

    • to enable blocking check the enable Blocking the access from infected computers to the servers. In the settings section Actions on computers set the blocked period during which the access from the infected computer to the server will be denied.

If you want an executable file to run automatically when blocking on the protected server check the box Run executable file and define the file starting parameters. 

    • to create the list of computers, which should never be blocked, in the group of settings Trusted computers create the list of the necessary computers and check the box Do not block specified computers.

 

    • to enable the mode to automatically switch to stricter Anti-Virus settings click the Additional button and check the box Increase security level if the number of computers exceeds. Define the number of infected computers; if this given number is exceeded then the virus outbreak prevention settings will automatically trigger (Anti-Virus security level gets stricter).

If the number of blocked computers gets less and the Anti-Virus should return to the previous settings check the box Restore security level if the number of computers is lower than and give the number.

 

Via Kaspersky Administration Kit:

1. Open the policy for Kaspersky Anti-Virus 6.0 for Windows Servers Enterprise Edition, which is active for the protected server.

2. go to the tab Blocking access from computers and: 

    • to enable blocking check Enable blocking the access from computers to the server. In the settings section Actions on computer set the time during which the access from the infected computer to the server will be denied.

If you want an executable file to run automatically when blocking on the protected server check the box Run executable file and define the file starting parameters. 

    • to create the list of computers, which should never be blocked, in the group of settings Trusted computers create the list of the necessary computers and check the box Do not block specified computers

 

    • to enable the mode to automatically switch to stricter Anti-Virus settings click the Additional button and check the box Increase security level if the number of computers exceeds. Define the number of infected computers; if this given number is exceeded then the virus outbreak prevention settings will automatically trigger (Anti-Virus security level gets stricter).

If the number of blocked computers gets less and the Anti-Virus should return to the previous settings check the box Restore security level if the number of computers is lower than and give the number.

3. Lock the settings in order to be applied on the protected server. Click the Apply button.


 Did the provided info help you?

                       

 Give your detailed feedback.

 

Kaspersky Lab

Copyright © 1997 - 2009 Kaspersky Lab
Site map  |   Contact us  |   International Support Service  |  Send us a suspected virus
Login Your Personal Cabinet  |   Register  |   FAQ for Personal Cabinet