Controls what
enters your network
For security reasons, you need to exercise control over what
kind of files enter your network. Yet, simply blocking all
downloads would be far too restricting for network users - and
would substantially reduce the usefulness of the Internet and
therefore employee productivity. Instead, GFI DownloadSecurity
for ISA Server enables you to define which file types should be
quarantined for administrator approval per user. You can also
use this feature to ensure that Internet bandwidth is not wasted
on useless downloads such as .mp3 files.
View
screenshotScans for viruses in HTTP and FTP
downloads
GFI DownloadSecurity scans all incoming HTTP/FTP downloads for
known viruses. Integrated with GFI DownloadSecurity for ISA
Server are two industrial-strength anti-virus engines. The
signature files are updated immediately after new virus
outbreaks become known.
Norman Virus Control & BitDefender
virus engines are included
GFI DownloadSecurity comes bundled with Norman Virus Control
5 & BitDefender. Norman Virus Control 5 is an industrial
strength virus engine that has received the 100% Virus
Bulletin award 16 times running. It also has ICSA and
Checkmark certification. BitDefender is a very fast and
flexible virus engine that excels in the number of formats
it recognizes and can scan. BitDefender is ICSA certified.
GFI DownloadSecurity automatically checks and updates the
Norman Virus Control & BitDefender definition files as they
become available. One year of updates is included in the
price of GFI DownloadSecurity. |
  |
McAfee virus engine optional
To achieve even greater security, it is possible to add the
renowned McAfee virus engine as a third anti-virus engine.
Adding the McAfee engine will cost approximately 20% of the GFI
DownloadSecurity price.
Quarantines - rather than blocks - suspicious file types
(.exe, .doc etc.)
GFI DownloadSecurity's rules engine allows you to quarantine
downloads such as .exe files, zip files and other files that
could contain harmful content, such as a virus, worm or Trojan.
GFI DownloadSecurity enables you to configure multiple file
checking rules and define what must be quarantined on a user or
group basis, giving you total flexibility in the way you choose
to check incoming files.
View
screenshot
Can block/check applications' hidden downloads
Some software applications automatically connect to their home
pages to download updates using HTTP tunneling. Although this
can reduce administration, it can also present a security risk
because unknown applications or Trojans can use the same
technique to download malicious files onto a user's PC, without
the user knowing. GFI DownloadSecurity can protect you against
the automatic downloading of files to users' PCs by known and
unknown applications. You can configure GFI DownloadSecurity to
allow updates from known/approved sites (e.g. Microsoft.com) and
block automatic updates from unknown sites.
Check/block incoming files by file type, not only by
extension
GFI DownloadSecurity blocks/quarantines files based on file type
(for example, executable) and file extension. Microsoft ISA
Server can only block by extension, meaning users could bypass
its file blocking system by renaming the extension. GFI
DownloadSecurity allows you to ensure that this does not happen
on your network.
Network-wide blocking of Java applets & Active X controls
ActiveX controls and Java applets are a huge security risk -
these programs can be Trojans or contain security holes that can
be exploited. Although users are prompted by their browser
whether they wish to run the ActiveX control or Java applet, a
user who is unaware of the risks could potentially infect your
network by downloading a control from an distrusted site. GFI
DownloadSecurity allows you to specify the sites from which you
trust ActiveX controls or Java applets and blocks all Java
applets and ActiveX controls from mistrusted/unknown sites. This
way, GFI DownloadSecurity secures your network from an
unsuspecting user making the wrong decision in downloading a
control or applet.
Approve downloads using the moderator client or your email
client
With GFI DownloadSecurity for ISA Server, you can approve
downloads and web pages that have been quarantined in 2 ways:
Using either the moderator client, or your email client. The
second method allows you to easily distribute the task of
approving/rejecting quarantined files to departmental
supervisors.
View
screenshot
Complete integration with ISA Server - Easy installation &
administration
GFI DownloadSecurity was built from the ground up to work
with ISA Server. It links in as an ISAPI extension and can
leverage features such as alerts, reporting and more that are
already found in ISA Server. You do not need to change anything
in your network configuration.
Cost-effective
GFI DownloadSecurity is very cost-effective compared to other
content filtering and anti-virus products. Because GFI
DownloadSecurity runs on ISA Server, no dedicated machine or
specialized know-how is needed.
How GFI DownloadSecurity for ISA Server works
Users will not notice GFI DownloadSecurity until they download a
file: Then GFI DownloadSecurity displays a download progress
dialog box and the download proceeds. Once the download is
complete, GFI DownloadSecurity scans the file for viruses. If
the file has no viruses and does not trigger a rule, the user
receives it immediately. If the file triggers a rule, it is put
into quarantine for administrator approval. Once approved, the
file is sent to the user as an email attachment/link. If
rejected, the user is notified.
View
screenshot |