简介
本文档介绍如何手动更新思科邮件安全设备(ESA)的防病毒流程。
如何立即强制下载Sophos或McAfee防病毒更新?
虽然根据设备服务更新的配置,定期进行防病毒更新,但如果您正在等待更新,可以自行启动防病毒更新。 默认情况下,更新程序服务每五分钟检查一次更新。 Cisco建议将此设置保留为默认更新间隔。
您可以通过GUI、安全服务(Security Services) >服务更新(Service Updates)查看设备服务更新。 从CLI运行updateconfig。 这将作为更新间隔列出。
要直接更新防病毒流程,请选择以下方法之一:
GUI
从GUI中可以从安全服务 > 防病毒启动更新,然后选择Sophos或McAfee。 从当前防病毒文件表中,单击立即更新按钮。
示例,使用Sophos防病毒:
CLI
从CLI中,您可以使用CLI命令antivirusupdate启动即时病毒更新,并选择您许可的防病毒进程、sophos或mcafee。
> antivirusupdate
Choose the operation you want to perform:
- MCAFEE - Request updates for McAfee Anti-Virus
- SOPHOS - Request updates for Sophos Anti-Virus
[]> sophos
Requesting check for new Sophos Anti-Virus updates.
在CLI中,还可以通过命令antivirusupdate force强制执行完全更新。 完整更新是指ESA联系思科更新服务器并拉出完整且最新的IDE,同时拉出完整且最新的防病毒引擎,并在设备后台重新应用此更新。
> antivirusupdate force
Sophos Anti-Virus updates:
Requesting forced update of Sophos Anti-Virus.
McAfee Anti-Virus updates:
Requesting update of virus definitions
确认
您可以从ESA上的CLI查看我运行的反病毒更新的过程tail updater_logs。这可以确保设备与思科更新服务器和清单的通信,并且允许您查看更新完成。
Wed Jul 23 09:38:58 2014 Info: Server manifest specified an update for sophos
Wed Jul 23 09:38:58 2014 Info: sophos was signalled to start a new update
Wed Jul 23 09:38:58 2014 Info: sophos processing files from the server manifest
Wed Jul 23 09:38:58 2014 Info: sophos started downloading files
Wed Jul 23 09:38:58 2014 Info: sophos waiting on download lock
Wed Jul 23 09:38:58 2014 Info: sophos acquired download lock
Wed Jul 23 09:38:58 2014 Info: sophos beginning download of remote file
"http://updates.ironport.com/sophos/ide/1406116201"
Wed Jul 23 09:39:03 2014 Info: sophos released download lock
Wed Jul 23 09:39:03 2014 Info: sophos successfully downloaded file "sophos/ide/1406116201"
Wed Jul 23 09:39:04 2014 Info: sophos waiting on download lock
Wed Jul 23 09:39:04 2014 Info: sophos acquired download lock
Wed Jul 23 09:39:04 2014 Info: sophos beginning download of remote file
"http://updates.ironport.com/sophos/libsavi/1402438439"
Wed Jul 23 09:41:07 2014 Info: sophos released download lock
Wed Jul 23 09:41:07 2014 Info: sophos successfully downloaded file
"sophos/libsavi/1402438439"
Wed Jul 23 09:41:07 2014 Info: sophos started applying files
Wed Jul 23 09:41:08 2014 Info: sophos updating component ide
Wed Jul 23 09:41:12 2014 Info: sophos updating component libsavi
Wed Jul 23 09:41:12 2014 Info: sophos updated engine,ide links successfully
Wed Jul 23 09:41:12 2014 Info: sophos cleaning up base dir /data/third_party/sophos
Wed Jul 23 09:41:12 2014 Info: sophos sending version details {'sophos': {'version': '5.01',
'ide': '2014072303'}} to hermes
Wed Jul 23 09:41:13 2014 Info: sophos verifying applied files
Wed Jul 23 09:41:13 2014 Info: sophos updating the client manifest
Wed Jul 23 09:41:13 2014 Info: sophos update completed
Wed Jul 23 09:41:13 2014 Info: sophos waiting for new updates
您将需要确保看到上面突出显示的行,这些行将表明请求的防病毒更新请求和更新成功。
思科鼓励启用Sophos防病毒扫描的客户订阅Sophos站点(http://www.sophos.com/virusinfo/notifications/)上的Sophos警报。订用直接从Sophos接收警报将确保您了解最新的病毒爆发及其可用的解决方案。
相关信息