<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: CDOT 8.3.1 vscan only passing .exe files to McAfee AV Scanner in ONTAP Discussions</title>
    <link>https://community.netapp.com/t5/ONTAP-Discussions/CDOT-8-3-1-vscan-only-passing-exe-files-to-McAfee-AV-Scanner/m-p/121741#M26100</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;can you change the vscan on-access -policy &amp;nbsp;to&amp;nbsp;&lt;STRONG&gt;scan-mandatory&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;vscan on-access-policy modify -vserver xxxxx_xxxxx&amp;nbsp;-policy-name &lt;SPAN&gt;template_test&lt;/SPAN&gt; -filters &lt;STRONG&gt;scan-mandatory&lt;/STRONG&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;you can control the vscan operation&amp;nbsp;by modifying&amp;nbsp;&lt;STRONG&gt;vscan-fileop-profile on the CIFS shares.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;cifs share modify -vserver xxxxx_xxxx -share-name tst_share -vscan-fileop-profile&lt;STRONG&gt;&amp;nbsp;no-scan standard strict writes-only&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i use writes-only in my environment.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;cifs share show -share-name &lt;SPAN&gt;share-name$&lt;/SPAN&gt; -fields vscan-fileop-profile&lt;BR /&gt;vserver share-name vscan-fileop-profile&lt;BR /&gt;------------- ------------------ --------------------&lt;BR /&gt;cluster share-name$ &lt;STRONG&gt;writes-only&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;let me know if this makes any difference.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Mani&lt;/P&gt;</description>
    <pubDate>Tue, 26 Jul 2016 13:32:03 GMT</pubDate>
    <dc:creator>manistorage</dc:creator>
    <dc:date>2016-07-26T13:32:03Z</dc:date>
    <item>
      <title>CDOT 8.3.1 vscan only passing .exe files to McAfee AV Scanner</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/CDOT-8-3-1-vscan-only-passing-exe-files-to-McAfee-AV-Scanner/m-p/121679#M26088</link>
      <description>&lt;P&gt;I have an 8040 Cluster running 8.3.1P1 and using McAfee VirusScan 8.8 with the current release of VSES for NetApp, NetApp VSCAN is configured as per NetApp best practice and the McAfee VSES is configured as 'we' beleve to be correct.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When we place eicar test pattern files in the CIFS shares only the files with a .exe extension are detected and deleted by the AV, we have tested with .txt .com and .vbs extension and they are not even scanned.&amp;nbsp; It looks likes they are not even being passed to AV server by VSCAN despite VSCAN being configured to scan all extensions.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Our 7-mode filer / McAfee AV detects all the test virus files,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Has anyone else experienced problems with AV scanning on CDOT 8.3.x and only .exe files being scanned.&lt;/P&gt;</description>
      <pubDate>Wed, 04 Jun 2025 19:50:29 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/CDOT-8-3-1-vscan-only-passing-exe-files-to-McAfee-AV-Scanner/m-p/121679#M26088</guid>
      <dc:creator>mn1970</dc:creator>
      <dc:date>2025-06-04T19:50:29Z</dc:date>
    </item>
    <item>
      <title>Re: CDOT 8.3.1 vscan only passing .exe files to McAfee AV Scanner</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/CDOT-8-3-1-vscan-only-passing-exe-files-to-McAfee-AV-Scanner/m-p/121721#M26094</link>
      <description>&lt;P&gt;HI,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you share the vscan profile output for teh specific vserver?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;vserver vscan on-access-policy show -vserver xx-xxx-xx&amp;nbsp;-policy-name&amp;nbsp;xxxx_xxxx&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Mani&lt;/P&gt;</description>
      <pubDate>Tue, 26 Jul 2016 06:31:12 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/CDOT-8-3-1-vscan-only-passing-exe-files-to-McAfee-AV-Scanner/m-p/121721#M26094</guid>
      <dc:creator>manistorage</dc:creator>
      <dc:date>2016-07-26T06:31:12Z</dc:date>
    </item>
    <item>
      <title>Re: CDOT 8.3.1 vscan only passing .exe files to McAfee AV Scanner</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/CDOT-8-3-1-vscan-only-passing-exe-files-to-McAfee-AV-Scanner/m-p/121724#M26096</link>
      <description>&lt;P&gt;Hi Mani&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is the output :&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Vserver: XXXX-template_test&lt;BR /&gt;Policy: template_test&lt;BR /&gt;Policy Status: on&lt;BR /&gt;Policy Config Owner: vserver&lt;BR /&gt;File-Access Protocol: CIFS&lt;BR /&gt;Filters: scan-execute-access&lt;BR /&gt;Max File Size Allowed for Scanning: 2GB&lt;BR /&gt;File Paths Not to Scan: -&lt;BR /&gt;File Extensions Not to Scan: -&lt;BR /&gt;File Extensions to Scan: *&lt;BR /&gt;Scan Files with No Extension: true&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;NetApp support have verified our config, the McAfee side only reports .exe files being passed to it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;&lt;P&gt;Matt&lt;/P&gt;</description>
      <pubDate>Tue, 26 Jul 2016 08:27:44 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/CDOT-8-3-1-vscan-only-passing-exe-files-to-McAfee-AV-Scanner/m-p/121724#M26096</guid>
      <dc:creator>mn1970</dc:creator>
      <dc:date>2016-07-26T08:27:44Z</dc:date>
    </item>
    <item>
      <title>Re: CDOT 8.3.1 vscan only passing .exe files to McAfee AV Scanner</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/CDOT-8-3-1-vscan-only-passing-exe-files-to-McAfee-AV-Scanner/m-p/121741#M26100</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;can you change the vscan on-access -policy &amp;nbsp;to&amp;nbsp;&lt;STRONG&gt;scan-mandatory&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;vscan on-access-policy modify -vserver xxxxx_xxxxx&amp;nbsp;-policy-name &lt;SPAN&gt;template_test&lt;/SPAN&gt; -filters &lt;STRONG&gt;scan-mandatory&lt;/STRONG&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;you can control the vscan operation&amp;nbsp;by modifying&amp;nbsp;&lt;STRONG&gt;vscan-fileop-profile on the CIFS shares.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;cifs share modify -vserver xxxxx_xxxx -share-name tst_share -vscan-fileop-profile&lt;STRONG&gt;&amp;nbsp;no-scan standard strict writes-only&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i use writes-only in my environment.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;cifs share show -share-name &lt;SPAN&gt;share-name$&lt;/SPAN&gt; -fields vscan-fileop-profile&lt;BR /&gt;vserver share-name vscan-fileop-profile&lt;BR /&gt;------------- ------------------ --------------------&lt;BR /&gt;cluster share-name$ &lt;STRONG&gt;writes-only&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;let me know if this makes any difference.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Mani&lt;/P&gt;</description>
      <pubDate>Tue, 26 Jul 2016 13:32:03 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/CDOT-8-3-1-vscan-only-passing-exe-files-to-McAfee-AV-Scanner/m-p/121741#M26100</guid>
      <dc:creator>manistorage</dc:creator>
      <dc:date>2016-07-26T13:32:03Z</dc:date>
    </item>
  </channel>
</rss>

