FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
Not applicable
Article Id 198423
Article
DescriptionBlocking Storm Worm from getting updates.
ComponentsAll FortiGate units.
Steps or Commands

The Storm Worm has been spreading wildly since the beginning of 2007 and turned many computers into spam spreading and DDoS zombies.

The worm mutates very quickly - every 30 minutes. FortiGuard is catching the worm as it mutates, however, with mutations happening so quickly it is hard for the AV signatures to catch up.

The worm uses the P2P eDonkey protocol to communicate with its Command and Control servers to get updates to be able to mutate. Therefore, if any of the PCs in your network is affected by this worm, you can use a FortiGate protection profile and firewall policy to block the eDonkey application and allow the AV signatures to catch up and eliminate the worm.

To block eDonkey

  1. Go to Firewall> Protection Profile.
  2. Edit a protection profile or add a new protection profile.
  3. Select the blue arrow for IM/P2P.
  4. Select Block for eDonkey.
  5. Save the protection profile.
  6. Go to Firewall > Policy
  7. Make sure the eDonkey-blocking protection profile is added to firewall policies that allow Internet access through your FortiGate unit.