Enabling and Disabling On-Access Network Scans

Prev Next

When malware detection is enabled, the following on-access malware scans options are available for your network files:

  • Scan on file read only

  • Scan on file write only

  • Scan on both file read and write

This section describes how to use the Web UI to enable and disable on access malware scans for your network files for all of your host endpoints or for select host sets in your environment. See the Endpoint Security (HX) REST API Guide for information on using the API to enable or disable on-access network scans.

Enabling Network File malware scans

The Scan Network Files feature is useful if you have file servers that do not have xAgent or other malware protection. The default setting for this feature is off and can be turned on to add protection to endpoints connected to your environment.

Important

If many of the network systems within the environment already have protection then it is not essential to activate network scanning.

Important

You must enable malware detection (Signature and Heuristics Detection) in the Web UI or the API before you can enable network file malware scans for all of your host endpoints or select host sets in your environment.

To enable network file malware scans for all of your host :
  1. Log in to the Web UI as an administrator.

  2. From the Admin menu, select Policies to access the Policies page.

  3. In the Policies table, click the link to access the Edit Policy page.

  4. Select the Malware Protection tab.

  5. Verify that the Signature and Heuristic Detection switch is ON.

    Policy_MalDetect_SH_Enable.png

    Important

    Malware detection (Signature and Heuristic Detection) must be enabled or the Scan network file option is not available.

  6. In the Malware Detection Options section, select the Scan network files checkbox to enable on-access scans for your network files.

    UI_Policy_MalD_ScanNetwork_Enable.png
  7. Select the best scan option for your environment.

    Options include:

    • Scan on file read only - Scans will occur more frequently.

    • Scan on file write only - Scans will occur less frequently.

    • Scan on both file read and write

  8. Click Save.

To select the best scan option for your environment:

There are a number of considerations when selecting the best scan option for your environment:

Performance considerations:

  • Performance is impacted by the amount of network connections to scan and the level of risk to the systems within the environment.

  • Performance is affected by the speed of the hardware.

Important

If you need to scan just a few individual endpoints, Trellix recommends that you limit the scan to those endpoints only. Scanning a network that includes both local and remote endpoints can degrade normal operation. To scan individual endpoints you must create a new host set with the individual endpoints, and then assign a custom policy to that host set. See Assigning Host Sets to Agent Policies and Creating a Custom Policy .

To enable network file malware scans for selected host sets:

Note

See Creating a Custom Policy for more information about using the Web UI to create a custom policy.

  1. Log in to the Web UI as an administrator.

  2. From the Admin menu, select Policies to access the Policies page.

  3. In the Policies table, click the link for the custom policy you want to modify.

  4. Select the Malware Protection tab.

  5. Verify that the Signature and Heuristic Detection switch is ON.

    Policy_MalDetect_SH_Enable.png

    Important

    Malware detection (Signature and Heuristic Detection) must be enabled or the Scan network file option is not available.

  6. In the Malware Detection Options section, select the Scan network files checkbox to enable on-access scans for your network files.

    UI_Policy_MalD_ScanNetwork_Enable.png
  7. Select the best scan option for your environment. Options include Scan on file read only, Scan on file write only, and Scan on both file read and write.

  8. Click Save.

Now you can assign host sets to the custom policy and set the policy priority level. See Assigning Host Sets to Agent Policies and Configuring Policy Priority Using the Web UI for more information.

Disabling Network File Malware Scans
To disable network files malware scans for all of your host endpoints:
  1. Log in to the Web UI as an administrator.

  2. From the Admin menu, select the Policies page.

  3. In the Policies table, click the link to access the Edit Policy page.

  4. Select the Malware Protection tab.

  5. In the Malware Detection Options section, clear the Scan network files checkbox to disable on-access scans for your network files.

  6. Click Save.

To disable network files malware scans for selected host sets:

Note

When you disable a setting in a custom policy, the setting is disabled for all host sets assigned to the policy. If you want select host sets to keep the original setting, you must create a new custom policy with the setting enabled and assign it to the selected host sets. See Creating a Custom Policy for more information about using the Web UI to create a custom policy.

  1. Log in to the Web UI as an administrator.

  2. From the Admin menu, select the Policies page.

  3. In the Policies table, click the link for the custom policy you want to modify.

  4. Select the Malware Protection tab.

  5. In the Malware Detection Options section, clear the Scan network files checkbox to disable on-access scans for your network files.

  6. Click Save.