- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
06-09-2015 05:57 AM
I have downloaded and installed the threat prevention license, configured daily download of antivirus and the other downloads, created security profiles and added them to my security profiles. Everything is working except for the antivirus, its downloading and installing the definitions every day but I am not getting any information in my threat monitor for antivirus. I don't think I missed anything but let me know if anyone has any ideas.
06-09-2015 07:24 AM
Hi
You can test Your config by Eicar test AV http://www.eicar.org/86-0-Intended-use.html
Regards
SLawek
06-09-2015 07:27 AM
It collecting maleware and vulnerability data just fine it the antivirus portion of the threat prevention that isn't showing anything I don't think the link you gave me will help me to assure that my antivirus configuration is correct and working.
06-09-2015 08:41 AM
Opps - dorry for misunderstanding.
What about Monitor>System logs close to time when update of AV definition should be picked up?
Did You try to manually upload AV update?
What version of PAN are You using?
Please share with us screenshot of Dynamic Update
Ragards
Slawek
06-09-2015 08:45 AM
My PA version is 6.1.1. Its downloading and installing just fine it just now showing any data in the threat monitor
06-09-2015 11:48 AM
Yes I have them created and added to my security policies
06-09-2015 11:56 AM
Lets do a test
Please try to dwonload http://www.eicar.org/download/eicar.com
If You really have proper configuration of AV profile atached to Your security polisy that allow Your computer to get internet access this Eicar file should be blocked
Please atache Your session detail with atempt to download Eicar file. My is:
06-10-2015 09:11 AM
I did the testing and confirmed with the PA service desk that it is configured correctly but still is not working correctly
06-10-2015 07:35 PM
Slawek,
Your screen print for the sample rule should have an Antivirus profile that blocks traffic. Like below:
Profile view:
Just saw it was missing in your example and may have been an oversight on your part. Hopefully this helps.
Phil
06-11-2015 05:26 AM
It is not necessary to have it set to block to have it work, it can also be set to alert
06-11-2015 05:32 AM
True. but having an Antivirus Profile of "none" will not work for testing. That was the main point I was suggesting. The block profile is just what we have in place.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!