• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

ClamAV de PfSense no me funciona

Español
3
13
1.9k
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • S
    starnix
    last edited by May 1, 2020, 11:12 AM

    Hola, ayer instalé tanto Squid como Squidguard en mi PfSense y me gustaría instalar el antivirus ClamAV para que así cuando intente abrir cualquier archivo no me deje, pues bien, he seguido los siguientes pasos de los dos vídeos que ven, el servicio me sale como activo pero cuando me meto en la web que ellos utilizan de prueba e intento descargar cualquier cosa, me deja sin ningún problema y no me sale la página que a ellos les sale.

    Los vídeos que utilicé son los siguientes: Instalación ClamAV
    Video largo de la instalación de ClamAV junto con SquidGuard y Squid

    Datos a tener en cuenta:

    • PfSense utilizado desde VirtualBox versión 2.4.4 p-3 (es una ISO)
    • Las pruebas las realizo desde máquinas virtuales Windows 8
    • Mi esquema de red es el siguiente: Salgo a internet a través de una WAN, de ella tengo dos LANS, una llamada Admin que es la LAN 1 que utilizo con una IP fija y luego tengo la LAN 2 llamada Clientes, esta LAN coge una IP automática con DHCP.
    • Los clientes solo pueden acceder a internet mediante portal cautivo, si no se logean y ponen nombre de usuario y contraseña correctamente, no les deja navegar.

    Esto es lo único que pienso que puedo tener mal y que por eso no me salga, esto es dentro de la configuración del Squid:

    login-to-view

    login-to-view

    login-to-view

    L 1 Reply Last reply May 1, 2020, 1:20 PM Reply Quote 0
    • D
      DaddyGo
      last edited by May 1, 2020, 12:02 PM

      ClamAV only works for http traffic, anyway, a firewall is not a good solution for virus protection.
      The proxy interface and the transparent proxy interface should be the LAN

      login-to-view

      Cats bury it so they can't see it!
      (You know what I mean if you have a cat)

      1 Reply Last reply Reply Quote 0
      • L
        lucasll @starnix
        last edited by May 1, 2020, 1:20 PM

        @starnix
        Prueba este test. Es un poco clásico, pero te ayudará.
        https://www.eicar.org --> link "download testfile"

        Enlace directo http (o sea, no https):
        http://2016.eicar.org/download/eicar.com

        1 Reply Last reply Reply Quote 0
        • S
          starnix
          last edited by May 1, 2020, 2:07 PM

          @lucasll
          Metiendome en la página https://www.eicar.org --> link "download testfile" y clickando sobre los zips, me deja ejecutar y guardarlo sin ningún problema.

          Si me meto en el enlace directo con http http://2016.eicar.org/download/eicar.com me sale lo siguiente:

          En la barra de direcciones aparece mi dominio acompañado de lo siguiente

          login-to-view
          http://2016.eicar.org/download/eicar.com

          login-to-view

          1 Reply Last reply Reply Quote 0
          • S
            starnix
            last edited by May 1, 2020, 2:10 PM

            @DaddyGo Does this mean that it will only work with pages that have an http certificate? well, nowadays almost no page uses http, now almost all uses https, then it is almost useless

            1 Reply Last reply Reply Quote 0
            • D
              DaddyGo
              last edited by May 1, 2020, 2:15 PM

              You understand the situation exactly well.
              ClamAV cannot scan https pages due to MITM

              Cats bury it so they can't see it!
              (You know what I mean if you have a cat)

              1 Reply Last reply Reply Quote 0
              • D
                DaddyGo
                last edited by May 1, 2020, 2:21 PM

                For a long time there was a problem with the redirect url and own pfSense system domain name,
                in case it works well, this page should get you

                login-to-view

                Cats bury it so they can't see it!
                (You know what I mean if you have a cat)

                1 Reply Last reply Reply Quote 0
                • S
                  starnix
                  last edited by May 1, 2020, 2:35 PM

                  @DaddyGo The person above gave me that same website, one with https and one with http.
                  If I try to enter the web page with https, I enter without problem and I can download the zips without any problem.

                  Instead in http I get the image that I have attached

                  L 1 Reply Last reply May 1, 2020, 3:08 PM Reply Quote 0
                  • D
                    DaddyGo
                    last edited by May 1, 2020, 2:52 PM

                    Yes this is a fairly common test page among IT professionals.
                    In my example, I used that too.
                    As I mentioned, this configuration is a problem (redirect url):

                    login-to-view

                    Anyway, try to upgrade to 2.4.5, it's your responsibility, but I can say that we've upgraded nearly 25 pfSense devices on our system without any problems. If you are using a virtual machine, be careful.

                    In 2.4.5 there is a pair of Squid and along with ClamAV update and patch

                    Cats bury it so they can't see it!
                    (You know what I mean if you have a cat)

                    S 1 Reply Last reply May 1, 2020, 3:41 PM Reply Quote 0
                    • L
                      lucasll @starnix
                      last edited by May 1, 2020, 3:08 PM

                      @starnix
                      También puedes hacer pruebas configurando el proxy explícitamente en el navegador. Es decir, sin modo transparente.

                      S 1 Reply Last reply May 1, 2020, 3:37 PM Reply Quote 0
                      • S
                        starnix @lucasll
                        last edited by May 1, 2020, 3:37 PM

                        @lucasll Para configurarlo como tu dices simplemente desactivo la opción de modo transparente y ya?

                        1 Reply Last reply Reply Quote 0
                        • S
                          starnix @DaddyGo
                          last edited by May 1, 2020, 3:41 PM

                          @DaddyGo I will try to update my pfsense in case that is what gives error

                          1 Reply Last reply Reply Quote 0
                          • D
                            DaddyGo
                            last edited by May 1, 2020, 4:24 PM

                            The non-transparent mode (implicit) requires multiple configurations, which can be inconvenient on a large system

                            https://docs.netgate.com/pfsense/en/latest/cache-proxy/wpad-autoconfigure-for-squid.html
                            https://www.ssltrust.com.au/help/setup-guides/setup-squid-proxy

                            Cats bury it so they can't see it!
                            (You know what I mean if you have a cat)

                            1 Reply Last reply Reply Quote 0
                            4 out of 13
                            • First post
                              4/13
                              Last post
                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.