Hi everyone-
New proxmox user here. I'm liking it a lot so far.
It seems that clamav is not scanning email attachments for me. When I use eicar at http://www.aleph-tec.com/eicar/index.php to send a message to myself, it gets through proxmox without issue. How can I troubleshoot this?
Here is syslog of the eicar email. I don't see any mention of Clam.
Virus detector settings:
Thanks for your help!
New proxmox user here. I'm liking it a lot so far.
It seems that clamav is not scanning email attachments for me. When I use eicar at http://www.aleph-tec.com/eicar/index.php to send a message to myself, it gets through proxmox without issue. How can I troubleshoot this?
Here is syslog of the eicar email. I don't see any mention of Clam.
Code:
Nov 16 18:25:30 mail01 postfix/postscreen[6836]: CONNECT from [205.233.73.32]:56620 to [{My IP}]:25
Nov 16 18:25:32 mail01 postfix/anvil[6402]: statistics: max connection rate 1/60s for (smtpd:8.12.53.104) at Nov 16 18:19:33
Nov 16 18:25:32 mail01 postfix/anvil[6402]: statistics: max connection count 1 for (smtpd:8.12.53.104) at Nov 16 18:19:33
Nov 16 18:25:32 mail01 postfix/anvil[6402]: statistics: max cache size 3 at Nov 16 18:20:04
Nov 16 18:25:36 mail01 postfix/postscreen[6836]: PASS NEW [205.233.73.32]:56620
Nov 16 18:25:36 mail01 postfix/smtpd[6847]: connect from batch.outbound.your-site.com[205.233.73.32]
Nov 16 18:25:36 mail01 postfix/smtpd[6847]: Anonymous TLS connection established from batch.outbound.your-site.com[205.233.73.32]: TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)
Nov 16 18:25:36 mail01 pmgpolicy[5092]: SPF says pass
Nov 16 18:25:36 mail01 postfix/smtpd[6847]: 82302C1079: client=batch.outbound.your-site.com[205.233.73.32]
Nov 16 18:25:36 mail01 postfix/cleanup[6853]: 82302C1079: message-id=<202011170125.0AH1P0Cd3126297@29c639b58d65.web.vm.your-site.com>
Nov 16 18:25:36 mail01 postfix/qmgr[20643]: 82302C1079: from=<eicar@aleph-tec.com>, size=2616, nrcpt=1 (queue active)
Nov 16 18:25:36 mail01 postfix/smtpd[6847]: disconnect from batch.outbound.your-site.com[205.233.73.32] ehlo=2 starttls=1 mail=1 rcpt=1 data=1 quit=1 commands=7
Nov 16 18:25:36 mail01 pmg-smtp-filter[6040]: 2020/11/16-18:25:36 CONNECT TCP Peer: "[127.0.0.1]:40642" Local: "[127.0.0.1]:10024"
Nov 16 18:25:36 mail01 pmg-smtp-filter[6040]: C127D5FB326908A97B: new mail message-id=<202011170125.0AH1P0Cd3126297@29c639b58d65.web.vm.your-site.com>
Nov 16 18:25:39 mail01 pmg-smtp-filter[6040]: C127D5FB326908A97B: SA score=0/5 time=2.514 bayes=undefined autolearn=ham autolearn_force=no hits=AWL(0.032),KAM_DMARC_STATUS(0.01),RCVD_IN_DNSWL_LOW(-0.7),SPF_HELO_PASS(-0.001),SPF_PASS(-0.001)
Nov 16 18:25:39 mail01 postfix/smtpd[6860]: connect from localhost.localdomain[127.0.0.1]
Nov 16 18:25:39 mail01 postfix/smtpd[6860]: 1DE56C1291: client=localhost.localdomain[127.0.0.1], orig_client=batch.outbound.your-site.com[205.233.73.32]
Nov 16 18:25:39 mail01 postfix/cleanup[6853]: 1DE56C1291: message-id=<202011170125.0AH1P0Cd3126297@29c639b58d65.web.vm.your-site.com>
Nov 16 18:25:39 mail01 postfix/qmgr[20643]: 1DE56C1291: from=<eicar@aleph-tec.com>, size=3236, nrcpt=1 (queue active)
Nov 16 18:25:39 mail01 pmg-smtp-filter[6040]: C127D5FB326908A97B: accept mail to <bryan@milestonefe.com> (1DE56C1291) (rule: default-accept)
Nov 16 18:25:39 mail01 postfix/smtpd[6860]: disconnect from localhost.localdomain[127.0.0.1] ehlo=1 xforward=1 mail=1 rcpt=1 data=1 commands=5
Nov 16 18:25:39 mail01 pmg-smtp-filter[6040]: C127D5FB326908A97B: processing time: 2.557 seconds (2.514, 0.022, 0)
Nov 16 18:25:39 mail01 postfix/lmtp[6854]: 82302C1079: to=<bryan@milestonefe.com>, relay=127.0.0.1[127.0.0.1]:10024, delay=2.7, delays=0.17/0.01/0/2.6, dsn=2.5.0, status=sent (250 2.5.0 OK (C127D5FB326908A97B))
Nov 16 18:25:39 mail01 postfix/qmgr[20643]: 82302C1079: removed
Nov 16 18:25:39 mail01 postfix/smtp[6861]: Trusted TLS connection established to milestonefe-com.mail.protection.outlook.com[104.47.58.110]:25: TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)
Nov 16 18:25:40 mail01 postfix/smtp[6861]: 1DE56C1291: to=<bryan@milestonefe.com>, relay=milestonefe-com.mail.protection.outlook.com[104.47.58.110]:25, delay=1.8, delays=0/0.01/0.75/0.99, dsn=2.6.0, status=sent (250 2.6.0 <202011170125.0AH1P0Cd3126297@29c639b58d65.web.vm.your-site.com> [InternalId=39324720568099, Hostname=MWHPR20MB1278.namprd20.prod.outlook.com] 11671 bytes in 0.235, 48.338 KB/sec Queued mail for delivery)
Nov 16 18:25:40 mail01 postfix/qmgr[20643]: 1DE56C1291: removed
Nov 16 18:25:45 mail01 pmgpolicy[20415]: starting policy database maintainance (greylist, rbl)
Nov 16 18:25:45 mail01 pmgpolicy[20415]: end policy database maintainance (8 ms, 1 ms)
Virus detector settings:
Thanks for your help!