Server admin

Virus scanning.

Farwing can check files that arrive from outside before they reach your folders. You connect a scanner: ClamAV, an ICAP scanner from your security vendor, or a command of your own. Virus scanning is included on every plan, Free mode too.

How it works

Every upload from outside the server lands first in a staging area inside the storage root. Outside means the browser, Farwing Desktop, a receive link, a package, or another server. Users cannot see the staging area. A file moves to its real place only when all of these are true:

  • The upload is complete.
  • The checksum matches.
  • The virus scan passes, or your scan policy allows it.

Event rules run after the scan, so automation never touches a file that has not passed.

Farwing does not include an antivirus engine. Scanning starts when you connect a scanner. Until then, files are not scanned.

Plans

Scanning is on every plan, Free mode included. Security is not an upsell. If your license ends and the server drops to Free mode, scanning keeps working. Only administrators can see the quarantine.

Choose a scanner

Open the virus scanning settings in the admin area and pick one scanner. Each has a Test connection button. Use it before you rely on the scanner.

ClamAV

ClamAV is a free virus scanner. Farwing talks to its clamd service. Farwing sends the file to clamd over the connection, so the scanner can run on another machine and does not need to see your storage.

  1. Run clamd. To run ClamAV beside Farwing in Docker, use the optional service file deploy/examples/compose.clamav.yml. Or use a clamd you already run.
  2. Raise ClamAV's size limits as described in Size limits.
  3. In Farwing, choose ClamAV and enter where clamd listens:
    • TCP: a host and port, such as clamav.example.com:3310.
    • Unix socket: the path of the socket, such as /run/clamav/clamd.ctl. The socket file must be visible inside the Farwing container, for example by sharing its folder as a volume.
  4. Choose Test connection.

Keep ClamAV's virus signatures up to date. ClamAV's own freshclam tool does this.

ICAP

ICAP is the standard way security products receive files to check. Use it to send files to your company's own scanning system.

  1. Choose ICAP and enter the service address, such as icap://scan.example.com:1344/avscan.
  2. Choose the mode. Farwing supports RESPMOD and REQMOD. RESPMOD is the default. Use the one your scanner's documentation names for scanning files.
  3. Choose Test connection.

Your own command

A custom scanner is any program that reads the file on its standard input and answers with an exit code. Enter the program and its arguments. Spaces separate them, and quotes group words that contain a space.

Exit codeFarwing treats the file as
0Clean
1Infected
Anything elseA scanner error. The scanner error policy decides.

The program must exist inside the Farwing container. In Docker, put scripts in the folder you mount at /scripts, as Event rules describes, or add the tool to the image. This script shows the contract. It is a demonstration, not a real scanner:

#!/bin/sh
# /scripts/demo-scan.sh
# A demonstration scanner, not a real one. Farwing sends the file on standard
# input. This script reports "infected" when the file contains the marker text
# used by the EICAR test file, and "clean" otherwise.
grep -aq 'EICAR-STANDARD-ANTIVIRUS-TEST-FILE'
case $? in
  0) exit 1 ;;  # marker found: infected
  1) exit 0 ;;  # marker not found: clean
  *) exit 2 ;;  # grep itself failed: error
esac

Which uploads are scanned

Each kind of upload has its own switch:

UploadDefault
Files sent through a receive linkOn
Packages from outside sendersOn
Uploads by your own usersOff
Files from other servers and hot foldersOff

Strangers' files are checked by default. Your own people are trusted until you say otherwise. A server-to-server copy or a hot folder has usually been scanned where it started.

What happens to each result

ResultWhat happens
CleanThe file is released from staging into its folder, and a file.arrived event fires.
InfectedThe file moves to the quarantine folder, which only administrators can see. An administrator and the owner of the link or package are told the file name and the threat name. The sender sees 1 file was not accepted and no details. A scan.blocked event fires, and Admin → Audit records it.
Too large for the scannerFollows your too-large policy: hold for an administrator (the default), or release marked Not scanned: too large.
Scanner error or timeoutFollows your scanner-error policy: hold for an administrator (the default), or release marked Not scanned: scanner error.

Every file and submission shows a scan status: Scanning…, Clean, Blocked, or Not scanned with the reason. The scanner may stay silent for 5 minutes by default before Farwing counts a timeout. It is a limit on silence, not on the whole scan, because a large file legitimately takes minutes.

Quarantine and held files

Infected files and held files wait where only administrators can see them. An administrator can release or delete each one. Every decision needs a reason, and the reason goes to Admin → Audit.

Size limits

Very large media files can be too big to scan. ClamAV cannot check a file above about 4 GB, whatever you configure. Plan for it.

ClamAV has its own size limits, and its defaults are far below the size of a typical video. Three settings in clamd.conf matter:

SettingWhat it limits
StreamMaxLengthThe largest stream clamd accepts. Farwing sends each file as a stream. A larger one is refused with INSTREAM size limit exceeded.
MaxFileSizeThe largest file ClamAV examines. It does not examine more than this of any one file.
MaxScanSizeThe most data ClamAV examines in one scan, counting everything unpacked from an archive.

Set all three as high as ClamAV allows. The largest round value under its ceiling is 4095M:

StreamMaxLength 4095M
MaxFileSize 4095M
MaxScanSize 4095M
# Wherever you run clamd, restart it after you edit its configuration.
# With the optional Compose service:
docker compose restart clamav

Farwing has its own matching setting, largest file to scan. It is 4095 MB by default. Farwing does not send a file above it to the scanner. It treats the file as too large, so you get a clear reason instead of a scanner refusal.

A file above the limit cannot be decided, and your too-large policy decides what happens to it:

  • Hold for an administrator (the default). The file does not reach its folder until an administrator releases or deletes it. This is the safe choice. A file that could not be checked is not a file that was checked.
  • Release, marked Not scanned: too large. The file goes through, and everyone who sees it can tell it was not scanned. Choose this only if holding large files would stop your work and you accept the risk.

The scanner-error policy works the same way for a scanner that is down or times out, and its default is also to hold. If you receive large video, expect some files to wait for an administrator, or choose the release policy for too-large files and rely on other controls for them.