This site requires JavaScript to be enabled

Examining an Antivirus profiles

485 views

5.0 - Last modified on 2026-09-25 Revised by Summer Scanlan

4.0 - Last modified on 2026-09-18 Revised by itsm kb_api

3.0 - Last modified on 2020-01-24 Revised by itsm kb_api

2.0 - Last modified on 2019-04-10 Revised by Admin Michael Baldwin

1.0 - Created on 2019-04-10 Authored by John Ives

Table of Contents

Overview

The Information Security Office (ISO) provides several security profiles for departments to utilize in their local firewall environments. To evaluate these for your unit, it is best to review the internal settings within Panorama. The steps below describe how to examine Antivirus profiles.

How to Examine Antivirus Profiles

  1. Log into https://panorama.net.berkeley.edu using single sign-on.
  2. Select the Objects tab from the top navigation bar.
  3. Under the Security Profiles menu in the left pane, select Antivirus.
    Panorama sidebar menu highlighting the Antivirus option under Security Profiles.
  4. ISO has developed two primary Antivirus profiles for campus use: ucbsec-standard and ucbsec-alerting.
    List of shared Antivirus profiles showing ucbsec-standard and ucbsec-alerting.

Protocol Decoders and Actions

By opening a profile (e.g., ucbsec-standard), you can view the list of protocols the firewall can decode to examine for malicious files. You can also see the Action taken if a virus is detected via standard signatures or WildFire appliances.

Settings view of ucbsec-standard showing decoders for HTTP, SMTP, FTP, etc.

Technical Note (POP3 and IMAP): For email protocols like POP3 and IMAP, the actions are always set to Alert. This is because attempting to kill the connection (Reset) would cause the client to immediately retry the transfer, creating an infinite loop. Additionally, blocking these connections would prevent the user from seeing any legitimate emails received after the malicious message.

Exceptions

There are two types of exceptions in an Antivirus profile. Note that ucbsec-standard does not contain exceptions as it applies campus-wide, but you may need these for custom departmental profiles:

A. Application Exceptions

Used when a specific application (identified by App-ID) requires different behavior even if it uses a standard protocol. For example, WebDAV might require an exception while operating over HTTP.

Application Exception tab in the AV profile showing WebDAV selected.

B. Virus Exceptions

Used if a specific virus behavior is being misidentified (false positive) or if a researcher needs to allow a specific threat for analysis. For example, allowing Def.Gen Command And Control Traffic.

Virus Exception tab showing a specific threat ID added to the allow list.


Additional Resources

For more details, visit the vendor documentation: Antivirus Security Profile Documentation.