Description

This article describes about why IDP is not blocking the EICAr files.

Solution

IDP detects and blocks threats based on predefined attack signatures and threat intelligence databases.

The EICAR file, however, is a standard antivirus test file designed to simulate malware detection and validate antivirus functionality. It is not classified as an attack that would typically be detected or blocked by IDP signatures.

 

If your objective is to detect and block EICAR files, you will need to configure and use the UTM Antivirus feature on the SRX.

For configuration details, please refer to the following document:

 

 https://www.juniper.net/documentation/us/en/quick-start/software/junos/content-security-qsg/content-security-qsg.pdf

 

 

 

 

 

Modification History

2024-09-18 : Article Created