This KB article explains the correct procedure to validate the Avira Anti-Virus (UTM AV) engine on Juniper SRX devices using the EICAR test file.
Customers often use eicar.org to verify that the Anti-Virus feature is functioning correctly. However, eicar.org now delivers the EICAR test file over HTTPS, which prevents the SRX from inspecting the downloaded file unless SSL Forward Proxy is configured. As a result, the download may succeed without being blocked, leading to the incorrect assumption that the Avira Anti-Virus engine is not working.
This article describes the correct validation methods for both HTTP and HTTPS traffic.
The Avira Anti-Virus engine can only inspect traffic that is visible to the SRX.
If SSL Forward Proxy is not configured, the SRX forwards the encrypted HTTPS traffic without inspection, and the Anti-Virus engine cannot detect or block the EICAR test file.
If SSL Forward Proxy is not configured:
show security utm anti-virus statistics
A successful block confirms that the Avira Anti-Virus engine is functioning correctly.
If you want to validate using eicar.org:
Without SSL Forward Proxy, the download from eicar.org will not be inspected because the traffic remains encrypted.