Help Center/ Cloud Firewall/ User Guide/ Attack Defense/ Configuring Virus Defense
Updated on 2026-09-23 GMT+08:00

Configuring Virus Defense

Scenario

Viruses are getting complex. Traditional antivirus measures cannot cope with them in a timely manner. CFW provides antivirus to detect and handle virus-infected files, so that they will not cause data damage, permission changes, or system breakdown.

CFW supports antivirus for HTTP, SMTP, POP3, FTP, IMAP4, and SMB protocols.

You can enable virus defense to block virus-infected files, and modify defense actions to improve security performance.

Specification Limitations

Antivirus is available only in the professional edition.

Enabling Antivirus to Block Virus-infected Files

  1. Enable at least one type of traffic protection.

  2. Log in to the CFW console.
  3. Click in the upper left corner of the management console and select a region.
  4. (Optional) Switch to another firewall instance. If there are multiple firewall instances, you can select a desired instance from the drop-down list in the upper left corner of the page.
  5. In the navigation pane on the left, choose Protection Policies > Attack Defense > Antivirus.
  6. Click to enable antivirus.

    After antivirus is enabled, Current Action is Disable by default. For details about how to change the action, see Modifying the Virus Defense Action for Better Protection Effect.

    You can click View Internet Border Antivirus Log to go to the log query page and view logs whose Attack Source Type is Antivirus at the Internet border.

    You can click View VPC Border Antivirus Log to go to the log query page and view logs whose Attack Source Type is Antivirus at the VPC border.

Modifying the Virus Defense Action for Better Protection Effect

  1. Log in to the CFW console.
  2. Click in the upper left corner of the management console and select a region.
  3. In the navigation pane on the left, choose Protection Policies > Attack Defense > Antivirus.
  4. In the rule list, click an action in the Operation column as needed.

    • Observe: The firewall checks the traffic of a protocol. If attack traffic is detected, the firewall records it in attack event logs but does not block it.
    • Block: The firewall checks the traffic of a protocol. If attack traffic is detected, the firewall records it in attack event logs and blocks it.
    • Disable: The firewall does not perform virus checks on the traffic of a protocol.

  5. In the displayed dialog box, click OK.

Follow-up Operations

For details about the protection overview, see Event Center. For details about logs, see Viewing Attack Event Logs.

References