Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Not applicable

Too slow with virus updates

Fortinet is too slow with virus updates. on friday 19.nov.2004 the the fortinet antivirus definition 4.507 can' t detect the new virus Sober.I Trend Micro can scan this new virus. Now by our customer we have a lot of infected workstations !!
8 REPLIES 8
Alex_Libenson
New Contributor

Have you sent a virus sample to Fortinet for analysis? http://www.fortinet.com/FortiProtectCenter/submit.html

Now I send the virus to you. My question is, why can scan Trend Micro and NAI this virus bevor 6 hours ?
Not applicable

I also send the Virus one Hour ago, but from my expierience with the last attack (Bagle.at) we have to wait till the US Stuff starts working. I think there ist no Fortinet Stuff in Europe.
Alex_Libenson

Bernd, according to information I got from Fortinet there is a European " virus hunters" team as well as one in Asia in addition to US, so they are monitoring new threats and releasing updates 24x7. As you can see with 4.508 they released it when it was night time in US. I can tell that during last year spped of updates increased alot. But still it' s sometimes far behind leading AV vendors. But I' ve seen cases when fortinet was much faster than others. Alex.
Alex_Libenson

Just checked TrendMicro (http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_SOBER.I&VSect=T) and FortiNet updates timing: TrendMicro released new update: Nov. 19, 2004 2:29:00 AM GMT -0800 FortiNet released new update 4.508: Nov. 19, 2004 3:57:00 AM GMT -0800 (FortiGate does not report timezone, but I guess it is the same -8 timezone) Difference is about one hour and a half. But both are really slow compared to AVP - their urgent update was released on 11:23 MSK which is 0:23 GMT-8 - more than 2 hours ahead of TrenMicro (and 30 minutes before TrendMicro discovered virus at 00:54).
Not applicable

Thing yourself as fortnet reselers and consider this demo for a client... You have a FooCompany Netwrok Antivirus and Fortigate. You want to perform a demo and the client has allready the fooCompany AV. where do you place the fortigate before or infrond of the FooCompany AV? Fortinet Sugest you place it behind. Why? because it will some day detect a virus the FooCompany has not, because it happened Fortinet had it first. So the custome will agree it is a good antivirus. The truth is if you put the othe way (first the fortigate then the FooCompany AV) you will have some day viruses being detected by FooCompany and not from Fortigate.. that is because this time they had it first. Unfortunately for fortigate they have to be in front. So they get all the critisism...
Not applicable

Your workstations Don' t have Anti-Virus SW on them?
Gareth
New Contributor

I visited the Support Centre in Nice earlier in the year (very early in the year). Even at that point they did have a team working on new virus signatures. This allows them to provide around the clock support. I believe there is some healthy competition between teams to knock out the signatures. We' ve seen the same thing in our company where virus' s get through just after they appear in the wild and are caught by internal virus software. BUT...like people said above, you don' t see how many times Fortinet are ahead of the rest. If you' ve got Fortinet and " another" you' ve got the best of both worlds. Probably worth using push updates so you don' t have that extra delay until your box polls for updates.
Labels
Top Kudoed Authors