View previous topic :: View next topic |
Author |
Message |
puffmd
Trooper
Joined: Mar 20, 2002
Posts: 16
Location: USA
|
Posted: Fri Apr 02, 2004 6:31 pm Post subject: B9, NOD32 IMON, and The Bat! |
|
|
Hello all,
I have the combination of B9, NOD32 IMON, and The Bat!. Now here is the question. Is there a way to configure these so NOD32 Imon only scans my e-mail once. I have everything set to listen on port 110. I have tried several different things but always end up with IMON scanning all e-mails either twice or not at all. I figure there is probably a way to do so with the port settings but I as of yet cannot figure it out.
Any help and/or advice on this would be appreciated.
Regards,
Kent
Last edited by puffmd on Mon Apr 05, 2004 8:14 pm, edited 1 time in total |
|
Back to top |
|
|
tosbsas
Trooper
Joined: Feb 27, 2003
Posts: 15
Location: Argentina
|
Posted: Fri Apr 02, 2004 11:00 pm Post subject: |
|
|
I did set Imon to port 9110 and The bat too, benign on port 110 - that did the trick
Ruben |
|
Back to top |
|
|
puffmd
Trooper
Joined: Mar 20, 2002
Posts: 16
Location: USA
|
Posted: Fri Apr 02, 2004 11:17 pm Post subject: |
|
|
Bat = 9110
IMON = 9110
B9 = 110
That does not work for me... The Bat! does not receive the e-mail....
Regards,
Kent |
|
Back to top |
|
|
Ikeb
General
Premium Member
Joined: Apr 20, 2003
Posts: 3531
Location: Canada
|
Posted: Sat Apr 03, 2004 12:47 am Post subject: |
|
|
If you can change the port# on each of these products, understand what you're doing and you can set them as you wish. The key to setting this up is to keep in mind that you're setting up a connection from the client to the first proxy, a second connection to the next in line, then another connection from the second proxy to the third, and finally from the third to the server.
Each connection between connected proxies MUST share the identical address and port # but each connection MUST have a unique address / port #. Each product vendor sets a "preferred" port # in the documentation but typically something has to change because the default is usually the loopback IP address and port 110. So in this case, if two vendors did that (very common, although note that FireTrust avoided this with B9), you have to change one of the connection's address/port#.
B9 sets up it's connection info via the hosts file, I dunno how the other two are configured. A lot of proxies have the address info for the NEXT connection passed via the uname field in the client account setup. It could happen that the whole connection chain must be passed that way. Note B9 configuration requires the user to add a .B9 extension to the POP server address. Now look in the host file and note that the POP server address.B9 has been assigned an address; something in the range 127.98.9.x, each account being assigned an address sequentially.
It probably gets more complicated when you have several proxies though 'cause they likely require that the proxy be pointed to via the mail client account. In fact, the other proxies may use the host file as well to establish domain name to IP address assignments. BTW, don't assume that all the addresses listed in the hosts file are in use. Some may be placed there and not removed when some product config is changed.
I'm not familiar with the other products and how they are configured but watch for the loopback address and same port# being configured for two of the required connections. That will put a stop to the data flow for sure. Try adding each one at a time and confirm that data is flowing before adding another proxy to the chain as a means of isolating the break in the proxy chain.
Sorry for the book. Hopefully you follow this. If not just post where I lost you.
_________________
I like SPAM ... on my sandwich! |
|
Back to top |
|
|
JimF
Cadet
Joined: May 20, 2003
Posts: 6
Location: USA
|
Posted: Sat Apr 03, 2004 8:51 pm Post subject: |
|
|
You can simplify things somewhat by upgrading to NOD32 version 2. The IMON does not use a proxy with an assigned POP port, but rather monitors everything that comes through the Winsock layer as I understand it. |
|
Back to top |
|
|
Ikeb
General
Premium Member
Joined: Apr 20, 2003
Posts: 3531
Location: Canada
|
Posted: Sat Apr 03, 2004 11:00 pm Post subject: |
|
|
Uhh, never considered Winsock being used to chain proxies but seems like a neat concept.
WRT your problem puffmd, perhaps this helps, perhaps not: http://www.mail-archive.com/[email protected]
_________________
I like SPAM ... on my sandwich! |
|
Back to top |
|
|
puffmd
Trooper
Joined: Mar 20, 2002
Posts: 16
Location: USA
|
Posted: Mon Apr 05, 2004 6:09 pm Post subject: |
|
|
Hello all,
I am using Nod32 v 2 already. All I can do in IMON is specify a port to listen on, can not use a proxy. With The Bat! I can specify a proxy and a port. And of course B9 sets up its own proxy in the Hosts file and then you use this proxy in The Bat!. You can specify the port in the B9 options.
Here is what seems to happen. POP3 is initiated on port 110 by The Bat! and IMON immediately intercepts and scans for viruses. Then B9 grabs it once IMON is finished and scans it, then releases it to The Bat! on port 110. IMON sees it again, so it grabs it the second time and scans again. This second scan by IMON is redundant since IMON has already scanned the email.
I do not see a way to change this, however I may be overlooking the obvious.
Thanks for all the help that I have received so far.
Regards,
Kent |
|
Back to top |
|
|
Ikeb
General
Premium Member
Joined: Apr 20, 2003
Posts: 3531
Location: Canada
|
Posted: Mon Apr 05, 2004 7:45 pm Post subject: |
|
|
So one question then is - can anyone report success using IMON as well as B9? Is this a known issue Hamish?
puffmd, how did you ascertain that IMON is interceding between TB! and B9 and also between B9 and the server?
BTW, while TB! initiates the connection request, the msg would come in the reverse direction. I.e. the server would pass the msg (via IMON?) to B9, which does it's thing, then passes the msg (via IMON again?) to TB!
_________________
I like SPAM ... on my sandwich! |
|
Back to top |
|
|
tosbsas
Trooper
Joined: Feb 27, 2003
Posts: 15
Location: Argentina
|
Posted: Mon Apr 05, 2004 7:52 pm Post subject: |
|
|
I really don't know why this is not working for you.
I am using Becky! Mail + benign + spampal +nod32 and have no problem at all after changing ports in nod - imon + becky! to 9110, leaving it in all of benign in 110
Mails look like they are checked first by b9, than imon and that's it
Can you get us some screens or mail them?? |
|
Back to top |
|
|
puffmd
Trooper
Joined: Mar 20, 2002
Posts: 16
Location: USA
|
Posted: Mon Apr 05, 2004 7:54 pm Post subject: |
|
|
It works the way it is except it is slower as each email gets scanned twice for viruses....
Here is what gets added to the end of each email....
__________ NOD32 1.701 (20040401) Information __________
This message was checked by NOD32 antivirus system.
http://www.nod32.com
----------------------------------------------------
This message has been processed by Firetrust Benign.
__________ NOD32 1.701 (20040401) Information __________
This message was checked by NOD32 antivirus system.
http://www.nod32.com
As you can see, Imon scans, then B9, and the IMON again...
Regards,
Kent |
|
Back to top |
|
|
Ikeb
General
Premium Member
Joined: Apr 20, 2003
Posts: 3531
Location: Canada
|
Posted: Mon Apr 05, 2004 7:59 pm Post subject: |
|
|
I thought you were using version 2.0 ... or is the "NOD32 1.701 ....." something else?
_________________
I like SPAM ... on my sandwich! |
|
Back to top |
|
|
puffmd
Trooper
Joined: Mar 20, 2002
Posts: 16
Location: USA
|
Posted: Mon Apr 05, 2004 8:07 pm Post subject: |
|
|
Yes, it is version 2.
The 1.701 refers to the virus signature database version.....
Regards,
Kent |
|
Back to top |
|
|
wandrinstar
Captain
Premium Member
Joined: Mar 07, 2004
Posts: 302
Location: Ireland
|
Posted: Tue Apr 06, 2004 8:35 am Post subject: |
|
|
Same as mine puffmd, when it works.
_________________
...Kieran |
|
Back to top |
|
|
JimF
Cadet
Joined: May 20, 2003
Posts: 6
Location: USA
|
Posted: Tue Apr 06, 2004 2:35 pm Post subject: |
|
|
tosbsas wrote: |
I am using Becky! Mail + benign + spampal +nod32 and have no problem at all after changing ports in nod - imon + becky! to 9110, leaving it in all of benign in 110
Mails look like they are checked first by b9, than imon and that's it
|
I hope not to confuse thing (much) further, but I have NOD32 version 2 and B9 both set to receive on port 110, and use Outlook Express as my email client after it passes through B9. I know from a trial I did a short time ago that NOD32 IMON intercepts a virus even before it gets to B9. Insofar as I know, it does not scan twice, although I have not looked for this specifically. Presumably if IMON were to miss a virus then B9 would catch it, but I have no way to test this myself.
|
|
Back to top |
|
|
tosbsas
Trooper
Joined: Feb 27, 2003
Posts: 15
Location: Argentina
|
Posted: Tue Apr 06, 2004 4:30 pm Post subject: |
|
|
No sweat - there is no question that it works
Once again: the screens I meant were of the bat and imon and benign. Important - in all possible places of benign you need to set 110
Ruben |
|
Back to top |
|
|
|