Virus scanning.
Farwing can check files that arrive from outside before they reach your folders. You connect a scanner: ClamAV, an ICAP scanner from your security vendor, or a command of your own. Virus scanning is included on every plan, Free mode too.
How it works
Every upload from outside the server lands first in a staging area inside the storage root. Outside means the browser, Farwing Desktop, a receive link, a package, or another server. Users cannot see the staging area. A file moves to its real place only when all of these are true:
- The upload is complete.
- The checksum matches.
- The virus scan passes, or your scan policy allows it.
Event rules run after the scan, so automation never touches a file that has not passed.
Farwing does not include an antivirus engine. Scanning starts when you connect a scanner. Until then, files are not scanned.
Plans
Scanning is on every plan, Free mode included. Security is not an upsell. If your license ends and the server drops to Free mode, scanning keeps working. Only administrators can see the quarantine.
Choose a scanner
Open the virus scanning settings in the admin area and pick one scanner. Each has a Test connection button. Use it before you rely on the scanner.
ClamAV
ClamAV is a free virus scanner. Farwing talks to its clamd
service. Farwing sends the file to clamd over the
connection, so the scanner can run on another machine and does not need
to see your storage.
-
Run
clamd. To run ClamAV beside Farwing in Docker, use the optional service filedeploy/examples/compose.clamav.yml. Or use aclamdyou already run. - Raise ClamAV's size limits as described in Size limits.
-
In Farwing, choose ClamAV and enter where
clamdlistens:- TCP: a host and port, such as
clamav.example.com:3310. - Unix socket: the path of the socket, such as
/run/clamav/clamd.ctl. The socket file must be visible inside the Farwing container, for example by sharing its folder as a volume.
- TCP: a host and port, such as
- Choose Test connection.
Keep ClamAV's virus signatures up to date. ClamAV's own
freshclam tool does this.
ICAP
ICAP is the standard way security products receive files to check. Use it to send files to your company's own scanning system.
- Choose ICAP and enter the service address, such as
icap://scan.example.com:1344/avscan. - Choose the mode. Farwing supports
RESPMODandREQMOD.RESPMODis the default. Use the one your scanner's documentation names for scanning files. - Choose Test connection.
Your own command
A custom scanner is any program that reads the file on its standard input and answers with an exit code. Enter the program and its arguments. Spaces separate them, and quotes group words that contain a space.
| Exit code | Farwing treats the file as |
|---|---|
| 0 | Clean |
| 1 | Infected |
| Anything else | A scanner error. The scanner error policy decides. |
The program must exist inside the Farwing container. In Docker, put
scripts in the folder you mount at /scripts, as
Event rules describes, or
add the tool to the image. This script shows
the contract. It is a demonstration, not a real scanner:
#!/bin/sh
# /scripts/demo-scan.sh
# A demonstration scanner, not a real one. Farwing sends the file on standard
# input. This script reports "infected" when the file contains the marker text
# used by the EICAR test file, and "clean" otherwise.
grep -aq 'EICAR-STANDARD-ANTIVIRUS-TEST-FILE'
case $? in
0) exit 1 ;; # marker found: infected
1) exit 0 ;; # marker not found: clean
*) exit 2 ;; # grep itself failed: error
esac
Which uploads are scanned
Each kind of upload has its own switch:
| Upload | Default |
|---|---|
| Files sent through a receive link | On |
| Packages from outside senders | On |
| Uploads by your own users | Off |
| Files from other servers and hot folders | Off |
Strangers' files are checked by default. Your own people are trusted until you say otherwise. A server-to-server copy or a hot folder has usually been scanned where it started.
What happens to each result
| Result | What happens |
|---|---|
| Clean | The file is released from staging into its folder, and a file.arrived event fires. |
| Infected | The file moves to the quarantine folder, which only administrators can see. An administrator and the owner of the link or package are told the file name and the threat name. The sender sees 1 file was not accepted and no details. A scan.blocked event fires, and Admin → Audit records it. |
| Too large for the scanner | Follows your too-large policy: hold for an administrator (the default), or release marked Not scanned: too large. |
| Scanner error or timeout | Follows your scanner-error policy: hold for an administrator (the default), or release marked Not scanned: scanner error. |
Every file and submission shows a scan status: Scanning…, Clean, Blocked, or Not scanned with the reason. The scanner may stay silent for 5 minutes by default before Farwing counts a timeout. It is a limit on silence, not on the whole scan, because a large file legitimately takes minutes.
Quarantine and held files
Infected files and held files wait where only administrators can see them. An administrator can release or delete each one. Every decision needs a reason, and the reason goes to Admin → Audit.
Size limits
ClamAV has its own size limits, and its defaults are far below the size
of a typical video. Three settings in clamd.conf matter:
| Setting | What it limits |
|---|---|
StreamMaxLength | The largest stream clamd accepts. Farwing sends each file as a stream. A larger one is refused with INSTREAM size limit exceeded. |
MaxFileSize | The largest file ClamAV examines. It does not examine more than this of any one file. |
MaxScanSize | The most data ClamAV examines in one scan, counting everything unpacked from an archive. |
Set all three as high as ClamAV allows. The largest round value under its ceiling is 4095M:
StreamMaxLength 4095M
MaxFileSize 4095M
MaxScanSize 4095M
# Wherever you run clamd, restart it after you edit its configuration.
# With the optional Compose service:
docker compose restart clamav
Farwing has its own matching setting, largest file to scan. It is 4095 MB by default. Farwing does not send a file above it to the scanner. It treats the file as too large, so you get a clear reason instead of a scanner refusal.
A file above the limit cannot be decided, and your too-large policy decides what happens to it:
- Hold for an administrator (the default). The file does not reach its folder until an administrator releases or deletes it. This is the safe choice. A file that could not be checked is not a file that was checked.
- Release, marked Not scanned: too large. The file goes through, and everyone who sees it can tell it was not scanned. Choose this only if holding large files would stop your work and you accept the risk.
The scanner-error policy works the same way for a scanner that is down or times out, and its default is also to hold. If you receive large video, expect some files to wait for an administrator, or choose the release policy for too-large files and rely on other controls for them.
Related
- Receive links
- Event rules
- Adding tools to the image
- Server admin
- The EICAR test file is a harmless file that every scanner reports as a virus. Send it through a receive link to check the whole chain.