HTTP Anti-Virus Proxy

Official HAVP Support Forum
Registration disabled, I'm tired of spambots. E-mail havp@hege.li if you have questions.
HAVP project is pretty much frozen/abandoned at this time anyway.


All times are UTC + 2 hours [ DST ]




Post new topic Reply to topic  [ 20 posts ]  Go to page 1, 2  Next
Author Message
 Post subject: Hardware Requirement
PostPosted: 19 Feb 2009 14:29 
Offline

Joined: 19 Feb 2009 14:23
Posts: 12
Hi All,

Can any one tell me what should be the hardware configuration for configuring HAVP.
There are 250 user in my company, i have configured HAVP on Intel 1.8 GHz with 2GB RAM, antivurus used is AVG free edition.
After configuring havp (Squid-HAVP-Squid) internet access slows down, so i revert back every thing.

Please help me in this regards, thanks in advance.

Regards,
V11683


Top
 Profile  
 
 Post subject: Re: Hardware Requirement
PostPosted: 19 Feb 2009 19:40 
Offline

Joined: 23 Apr 2008 09:36
Posts: 101
Hi v11683 and welcome in HAVP forum!

Your hardware should be enough! Have you seen your top status, while havp was running?
I can say, i made the same expirience with running havp in a sandwich, it slows down my requests, but it was acceptable. (I should say, i have no experience with AVG, my favorite is clamav.)
The question is, how much slows down your requests, if you are using havp in sandwich?

The other option is, to configure havp with this schematics: squid -> havp or havp -> squid, where i recommend to take squid -> havp as configuration.

Greetings, karesmakro


Top
 Profile  
 
 Post subject: Re: Hardware Requirement
PostPosted: 20 Feb 2009 09:29 
Offline

Joined: 19 Feb 2009 14:23
Posts: 12
Thanks karesmakro for quick reply.
After configuring HAVP in sandwich, the internet access speed was down, which was not acceptable.

Well i will try, the option you suggested, but one query -
"How much clamav is good? I have tested one virus in many antivirus system, and every antivirus detected it except clamav, that's why i used AVG free edition."

Thanks, Vinod :D


Top
 Profile  
 
 Post subject: Re: Hardware Requirement
PostPosted: 20 Feb 2009 10:00 
Offline

Joined: 23 Apr 2008 09:36
Posts: 101
My expirience about clamav is very good. I use it in much network areas without having problems to this day. When you made your tests, was this virus in archive? Did you used havp with your tests? Clamav needs the right options to for e.g. scan archives ...
Another option for clamav which i like is, you can use third party signature from sanesecurity ...
I know about some people, the use more then one virus scanner to protect there network.

What i might find interesting, could you post the relevant part of your squid configuration, which you used for sandwich?
As i said, i used a sandwich for about half a year with minimal loss of speed.

greetings, kare


Top
 Profile  
 
 Post subject: Re: Hardware Requirement
PostPosted: 20 Feb 2009 11:42 
Offline

Joined: 19 Feb 2009 14:23
Posts: 12
Hi, Here i am attaching the Configuration file i have used, take a look at it.

I configured HAVP for both AVG as wll clamav, AVG was giving the result, while clamav didn't, even after downloading that perticular zip archieve, and after unzipping and directly scanning the infected file, clamav just saying OK after performing scanning.
For your reference, i tried to check the file downloaded from below link.

http://keygen.us/get.shtml?313152

Thanks, Vinod


Top
 Profile  
 
 Post subject: Re: Hardware Requirement
PostPosted: 20 Feb 2009 11:43 
Offline

Joined: 19 Feb 2009 14:23
Posts: 12
My HAVP configuration:


Squid Configuration File

##################################
http_port 3128 transparent
http_port 127.0.0.1:8090

acl HAVP_PORT myport 8090
no_cache deny !HAVP_PORT
cache_peer localhost parent 8081 0 no-query no-digest no-netdb-exchange default

always_direct allow SSL_ports
cache_peer_access 127.0.0.1 allow localhost
cache_peer_access localhost allow !SSL_ports
cache_peer_access localhost deny all

never_direct allow !SSL_ports
always_direct allow HAVP_PORT
always_direct deny all

#My ACL List

##################################

HAVP Configuration File

##################################
SERVERNUMBER 15
MAXSERVERS 50
PARENTPROXY 127.0.0.1
PARENTPORT 8090
PORT 8081
MAXSCANSIZE 10000000

##### AVG Socket Scanner

#ENABLEAVG false
ENABLEAVG true

# AVG daemon needs to run on the same server as HAVP
#
# Default:
# AVGSERVER 127.0.0.1
# AVGPORT 55555
##################################


Top
 Profile  
 
 Post subject: Re: Hardware Requirement
PostPosted: 20 Feb 2009 12:07 
Offline

Joined: 23 Apr 2008 09:36
Posts: 101
This was my answer from havp about your test site:Access to the page has been denied because the following virus was detected ClamAV: MBL_100185.UNOFFICIAL (description)
This virus was found by third party signature.

Your configuration looks good to me.
Perhaps you should really try to take configuration squid -> havp to speed up your requests.


Top
 Profile  
 
 Post subject: Re: Hardware Requirement
PostPosted: 20 Feb 2009 12:14 
Offline

Joined: 19 Feb 2009 14:23
Posts: 12
I have tried earlier to setup squid -> havp, but failed, can u plz send the configuration file.

Good to see that clam has detected it as Virus, Now, how can i integrate "third party signature" with my clamav antivirus.

Thanks, Vinod


Top
 Profile  
 
 Post subject: Re: Hardware Requirement
PostPosted: 21 Feb 2009 10:54 
Offline

Joined: 23 Apr 2008 09:36
Posts: 101
Before you change your (sandwich) configuration, please test you old one with:
in havp:
Code:
SERVERNUMBER 40
MAXSERVERS 150

and change squid configuration like my post (next to last thread):
http://havp.hege.li/forum/viewtopic.php?f=3&t=399
Note: this configuration options are for squid 2.6 and higher

squid -> havp configuration should be similar to described one, without PARENTPROXY in havp and the entries for second port of squid.

Third party description could be found on
http://www.sanesecurity.co.uk/clamav/

regards, kare


Top
 Profile  
 
 Post subject: Re: Hardware Requirement
PostPosted: 21 Feb 2009 17:22 
Offline
HAVP Developer

Joined: 27 Feb 2006 18:12
Posts: 687
Location: Finland
Have you changed avg.conf numOfDaemons ?

Some scanners free version was limited to only 2 concurrent scans, slowing everything down.. it might have been AVG, can't remember right now..


Top
 Profile  
 
 Post subject: Re: Hardware Requirement
PostPosted: 23 Feb 2009 16:45 
Offline

Joined: 19 Feb 2009 14:23
Posts: 12
I have change my antivirus to clamav and also updated the third party signatures, and everything is working fine.

The problem with AVG was unavailability of AVG scan deamons.

Thanks to both for helping me a lot.

Regards,
Vinod


Top
 Profile  
 
 Post subject: Re: Hardware Requirement
PostPosted: 27 Feb 2009 08:43 
Offline

Joined: 19 Feb 2009 14:23
Posts: 12
Hi Again,

The HAVP configuration was working fine for last 4 days, but today i am getting the error, clamd scanner not available.

I have checked, clamd service was not running, and as i started the service it gives below error:

service clamd start
Starting clamd: /bin/bash: line 1: 20535 File size limit exceeded/usr/sbin/clamd
[FAILED]


Please help me in this regard.

Thanks, Vinod


Top
 Profile  
 
 Post subject: Re: Hardware Requirement
PostPosted: 27 Feb 2009 10:53 
Offline

Joined: 23 Apr 2008 09:36
Posts: 101
Hi,
you have to create a logrotate entry for clamd.log and all is fine!
Log file size could be set by following option in clamd.conf too:
Code:
LogFileMaxSize

wish a nice weekend.

greetings


Top
 Profile  
 
 Post subject: Re: Hardware Requirement
PostPosted: 27 Feb 2009 11:00 
Offline

Joined: 19 Feb 2009 14:23
Posts: 12
I have already set the parameter to 100MB, and current log size of my clamd.log file is about 70MB.

Thanks, Vinod
Happy Weekends.


Top
 Profile  
 
 Post subject: Re: Hardware Requirement
PostPosted: 27 Feb 2009 11:04 
Offline

Joined: 23 Apr 2008 09:36
Posts: 101
100MB is a little bit crazy. I recommend you to set this to 10M maximum.
Did you enabled debug mode? 70MB about 4 days is a little bit much!


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 20 posts ]  Go to page 1, 2  Next

All times are UTC + 2 hours [ DST ]


Who is online

Users browsing this forum: Google [Bot] and 2 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
Powered by phpBB® Forum Software © phpBB Group