These are all good points.
You will want to do the following:
1. Under Proxy Options, change the protocol inspection ports to " Any" for each listing
2. Enable block botnet connections in AV
3. Block FortiGuard categories under Security Risk, and also enable " Rate URLs by Domain and IP Address"
4. Block Botnet applications in App Control
(OPTIONAL because there are several considerations to doing so - enable deep SSL inspection).
The reason behind these recommendations is that it requires a layered approach to solve the problem.
1. You want to inspect the various protocols on any port because it is easy to run HTTP on a different port
2. Blocking Botnet under AV takes care of signature based bots
3. Blocking " Security Risk" means any site marked malicious by FortiGuard is automatically blocked
4. Blocking Botnet under App Control takes care of behavior based bots
It is becoming increasingly common for attacks to run over SSL enabled protocols as well, so for absolute best coverage you will want to enable this as well. However this is not something you should do lightly. SSL Decryption takes planning and some trial and error to accomplish - that is not a FortiGate thing but rather the same process is needed for ANY product that does SSL decryption. There is so much to cover on this topic I won' t do so here in this post, only to say please read carefully the documentation on SSL Decryption before you enable it. Don' t just turn it on.
Once you go through the process and enable it, however, you will then have a layer of protection that the majority of network security installations are not able to block, and you will make yourself safer against things like zero-day attacks.
If you do all these things and you find that Conflicker is getting by the Fortigate, please do a packet capture of the issue in action, and then open a TAC case so we can review this for you and resolve your problem, because it should be able to block it. Make sure you give a backup of the FortiGate config as well as a diag debug report / exe tac report when you do so.
Hope this helps. Thanks!
--
Sean Toomey, CISSP FCNSP
Consulting Security Engineer (CSE)
FORTINET— High Performance Network Security