GFI DownloadSecurity
 
 

(Previously LANguard for ISA Server)

Brochure GFI DownloadSecurity for ISA Server brochure

Whitepapers - Why downloads content checking: Keeping corporate downloads virus-free
This white paper examines the security threats facing companies due to viruses that can be contracted through HTTP and FTP downloads. The paper explains why it is important to scan corporate downloads at ISA Server level and describes how GFI DownloadSecurity, which is built on ISA Server, does this.

Reviews

 

Control what files enter your network via FTP/HTTP & ensure they are virus-free

The Internet is a must-have tool for most employees within a company. Online ordering of products, customer & product research and more make it a requirement for most white collar employees to have HTTP and FTP access from the workplace. However, this introduces a huge security risk: Users can now download all types of files that can include Trojans, viruses or objectionable material, and more. Simply blocking all downloads at firewall level would significantly reduce employee productivity.

Rather than blocking file downloads completely, GFI DownloadSecurity for ISA Server checks all downloads for viruses and gives you the power to control what type of files enter your network, from where and for whom.

Using GFI DownloadSecurity's powerful rules engine, you can configure rule sets based on file type and user that allow you to quarantine dangerous files for administrator approval.

GFI DownloadSecurity for ISA Server Features
 
Controls what enters your network
For security reasons, you need to exercise control over what kind of files enter your network. Yet, simply blocking all downloads would be far too restricting for network users - and would substantially reduce the usefulness of the Internet and therefore employee productivity. Instead, GFI DownloadSecurity for ISA Server enables you to define which file types should be quarantined for administrator approval per user. You can also use this feature to ensure that Internet bandwidth is not wasted on useless downloads such as .mp3 files. View screenshot

Scans for viruses in HTTP and FTP downloads
GFI DownloadSecurity scans all incoming HTTP/FTP downloads for known viruses. Integrated with GFI DownloadSecurity for ISA Server are two industrial-strength anti-virus engines. The signature files are updated immediately after new virus outbreaks become known.

Norman Virus Control & BitDefender virus engines are included
GFI DownloadSecurity comes bundled with Norman Virus Control 5 & BitDefender. Norman Virus Control 5 is an industrial strength virus engine that has received the 100% Virus Bulletin award 16 times running. It also has ICSA and Checkmark certification. BitDefender is a very fast and flexible virus engine that excels in the number of formats it recognizes and can scan. BitDefender is ICSA certified. GFI DownloadSecurity automatically checks and updates the Norman Virus Control & BitDefender definition files as they become available. One year of updates is included in the price of GFI DownloadSecurity. 

McAfee virus engine optional
To achieve even greater security, it is possible to add the renowned McAfee virus engine as a third anti-virus engine. Adding the McAfee engine will cost approximately 20% of the GFI DownloadSecurity price.

Quarantines - rather than blocks - suspicious file types (.exe, .doc etc.)
GFI DownloadSecurity's rules engine allows you to quarantine downloads such as .exe files, zip files and other files that could contain harmful content, such as a virus, worm or Trojan. GFI DownloadSecurity enables you to configure multiple file checking rules and define what must be quarantined on a user or group basis, giving you total flexibility in the way you choose to check incoming files. View screenshot

Can block/check applications' hidden downloads
Some software applications automatically connect to their home pages to download updates using HTTP tunneling. Although this can reduce administration, it can also present a security risk because unknown applications or Trojans can use the same technique to download malicious files onto a user's PC, without the user knowing. GFI DownloadSecurity can protect you against the automatic downloading of files to users' PCs by known and unknown applications. You can configure GFI DownloadSecurity to allow updates from known/approved sites (e.g. Microsoft.com) and block automatic updates from unknown sites.

Check/block incoming files by file type, not only by extension
GFI DownloadSecurity blocks/quarantines files based on file type (for example, executable) and file extension. Microsoft ISA Server can only block by extension, meaning users could bypass its file blocking system by renaming the extension. GFI DownloadSecurity allows you to ensure that this does not happen on your network.

Network-wide blocking of Java applets & Active X controls
ActiveX controls and Java applets are a huge security risk - these programs can be Trojans or contain security holes that can be exploited. Although users are prompted by their browser whether they wish to run the ActiveX control or Java applet, a user who is unaware of the risks could potentially infect your network by downloading a control from an distrusted site. GFI DownloadSecurity allows you to specify the sites from which you trust ActiveX controls or Java applets and blocks all Java applets and ActiveX controls from mistrusted/unknown sites. This way, GFI DownloadSecurity secures your network from an unsuspecting user making the wrong decision in downloading a control or applet.

Approve downloads using the moderator client or your email client
With GFI DownloadSecurity for ISA Server, you can approve downloads and web pages that have been quarantined in 2 ways: Using either the moderator client, or your email client. The second method allows you to easily distribute the task of approving/rejecting quarantined files to departmental supervisors. View screenshot

Complete integration with ISA Server - Easy installation & administration
GFI DownloadSecurity was built from the ground up to work with ISA Server. It links in as an ISAPI extension and can leverage features such as alerts, reporting and more that are already found in ISA Server. You do not need to change anything in your network configuration.

Cost-effective
GFI DownloadSecurity is very cost-effective compared to other content filtering and anti-virus products. Because GFI DownloadSecurity runs on ISA Server, no dedicated machine or specialized know-how is needed.

How GFI DownloadSecurity for ISA Server works
Users will not notice GFI DownloadSecurity until they download a file: Then GFI DownloadSecurity displays a download progress dialog box and the download proceeds. Once the download is complete, GFI DownloadSecurity scans the file for viruses. If the file has no viruses and does not trigger a rule, the user receives it immediately. If the file triggers a rule, it is put into quarantine for administrator approval. Once approved, the file is sent to the user as an email attachment/link. If rejected, the user is notified. View screenshot

System Requirements
  • Microsoft ISA Server
  • Windows 2000 Server