Anti-Malware and Sandbox configuration on USG200H

supportpc
supportpc Posts: 15  Freshman Member
First Comment Friend Collector First Anniversary

Hi,

I'm trying to configure the anti-malware module and the sandbox module without success.
Both modules are enabled, but the statistics remain empty, and if I run a test with the eicar file, it passes through the firewall.

I don't have any data in the statistics, and I don't have any events in the logs.
Does anyone have any ideas on what I've probably done wrong?

Obviously the license for both modules is active and valid until 2026.

Here is the configuration which seems simple to me.

image.png image.png

All Replies

  • Zyxel_James
    Zyxel_James Posts: 682  Zyxel Employee
    Zyxel Certified Network Administrator - Security Zyxel Certified Network Administrator - Nebula Zyxel Certified Sales Associate 100 Answers

    May I know how you tested it? Did the download come from internet to a LAN host?
    Or we can arrange private remote session to look into this?

  • supportpc
    supportpc Posts: 15  Freshman Member
    First Comment Friend Collector First Anniversary

    Hi @Zyxel_James ,

    Here's my test protocol:

    I have a rule with a basic Content Filter applied, allowing internet access from a PC on the internal network via the internal subnet 192.168
    168.0/24, and I'm trying two things:

    • The first is to download the test files from the EICAR website ( https://www.eicar.org/download-anti-malware-testfile )
    • The second is to download a .zip file from another site, such as Putty or Winscp website

    In all cases, the file is successfully downloaded to the PC, even though in theory it should be captured and deleted directly by the firewall. Unless I've misunderstood the purpose of the two modules.