Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Squid C-ICAP Virus Table & Malware Virus Test File in HTTP CAUGHT!!

    Scheduled Pinned Locked Moved Cache/Proxy
    4 Posts 1 Posters 944 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • JonathanLeeJ
      JonathanLee
      last edited by JonathanLee

      Hello Fellow Netgate Community, Happy New Year!!!!!

      Quick question, Has anyone ever seen anything different inside of the virus table area of Squid under the real time tab? Is it normal to have this area seen in the image below empty? My Squid is setup and running in transparent mode and this section is always empty. Does this only populate when a virus is found by the proxy?
      Screen Shot 2021-12-31 at 9.53.06 AM.png
      (Image: Virtus Table)

      Please if anyone has seen something different or caught a virus post a reply. Does Squid have a test file to make sure the anti virus is working?

      Make sure to upvote

      JonathanLeeJ 1 Reply Last reply Reply Quote 0
      • JonathanLeeJ
        JonathanLee @JonathanLee
        last edited by

        @jonathanlee

        Virus Logs.JPG

        Please let me know if anyone has ever seen a virus caught in pfSense Squid Proxy's Anti Virus

        Make sure to upvote

        JonathanLeeJ 1 Reply Last reply Reply Quote 0
        • JonathanLeeJ
          JonathanLee @JonathanLee
          last edited by

          @jonathanlee

          Even with full use of Squidguard I still show no activity of scans or downloads in virus logs.

          Virus Logs2.JPG

          Make sure to upvote

          JonathanLeeJ 1 Reply Last reply Reply Quote 0
          • JonathanLeeJ
            JonathanLee @JonathanLee
            last edited by

            @jonathanlee

            443 not working.JPG

            (Image: Virus Protection working only with HTTP)

            If I download the file with HTTPS it does not catch it. However notice I am running SSL intercept with the logs seen above.

            clamavcaught.JPG

            (Caught: Only working currently for me with HTTP)

            HTTPS will bypass this even with the certificates installed and proxy running.

            Amazing to see it run half way there !!!

            Make sure to upvote

            1 Reply Last reply Reply Quote 0
            • JonathanLeeJ JonathanLee referenced this topic on
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.