To configure the defense, select your product from the list below and follow the related protection steps.
Security Gateway R70
How Can I Protect My Network?
1. In the IPS tab, click Protections > By Protocol > Web Intelligence > HTTP Protocol Inspection.
2. In the right pane, double-click the Header Rejection protection.
3. In the Protection Details window, click on Edit. Choose the protection's Action (Override IPS Policy with: Prevent/Detect).
4. Under Additional Settings > Header Rejection, enable the following protections:
iWonBar 1
Trojan-Downloader: Win32.Delf.phh
5. In the IPS tab, click Protections > By Protocol > Web Intelligence > Malicious Code.
6. In the right pane, double-click the General HTTP Worm Catcher protection.
7. In the Protection Details window, click on Edit. Choose the protection's Action (Override IPS Policy with: Prevent/Detect).
8. Under Additional Settings > Block HTTP Worms, enable the following protections:
iWonBar
Trojan-Downloader: Win32.Delf.phh 1
Trojan-Downloader: Win32.Delf.phh 2
Trojan-Downloader: Win32.Delf.phh 3
Trojan-Downloader: Win32.Delf.phh 4
9. Install policy on all modules.
How Do I Know if My Network is Under Attack?
SmartView Tracker will log the following entries:
Attack Name: Header Rejection
Attack Information:
iWonBar 1
Trojan-Downloader: Win32.Delf.phh
Attack Name: HTTP Worm Catcher
Attack Information:
iWonBar
Trojan-Downloader: Win32.Delf.phh 1
Trojan-Downloader: Win32.Delf.phh 2
Trojan-Downloader: Win32.Delf.phh 3
Trojan-Downloader: Win32.Delf.phh 4
VPN-1 NGX R65 & R62
How Can I Protect My Network?
1. In the SmartDefense tab, click Web Intelligence > HTTP Protocol Inspection > Header Rejection.
2. In the Header Rejection configuration pane, under Header Rejection Settings > Mode, check Active.
3. Enable the following protections:
iWonBar 1
Trojan-Downloader: Win32.Delf.phh
4. In the SmartDefense tab, click Web Intelligence > Malicious Code > General HTTP Worm Catcher.
5. In the General HTTP Worm Catcher configuration pane, under Settings > Mode, check Active.
6. Enable the following protections:
iWonBar
Trojan-Downloader: Win32.Delf.phh 1
Trojan-Downloader: Win32.Delf.phh 2
Trojan-Downloader: Win32.Delf.phh 3
Trojan-Downloader: Win32.Delf.phh 4
7. Install policy on all modules.
How Do I Know if My Network is Under Attack?
SmartView Tracker will log the following entries:
Attack Name: Header Rejection
Attack Information:
iWonBar 1
Trojan-Downloader: Win32.Delf.phh
Attack Name: HTTP Worm Catcher
Attack Information:
iWonBar
Trojan-Downloader: Win32.Delf.phh 1
Trojan-Downloader: Win32.Delf.phh 2
Trojan-Downloader: Win32.Delf.phh 3
Trojan-Downloader: Win32.Delf.phh 4
VPN-1 NGX R61 & R60
How Can I Protect My Network?
1. In the Web Intelligence tree, click HTTP Protocol Inspection > Header Rejection.
2. Enable the following protections:
iWonBar 1
Trojan-Downloader: Win32.Delf.phh
3. In the Web Intelligence tree , click Malicious Code > General HTTP Worm Catcher.
4. Enable the following protections:
iWonBar
Trojan-Downloader: Win32.Delf.phh 1
Trojan-Downloader: Win32.Delf.phh 2
Trojan-Downloader: Win32.Delf.phh 3
Trojan-Downloader: Win32.Delf.phh 4
5. Install policy on all modules.
How Do I Know if My Network is Under Attack?
SmartView Tracker will log the following entries:
Attack Name: Header Rejection
Attack Information:
iWonBar 1
Trojan-Downloader: Win32.Delf.phh
Attack Name: HTTP Worm Catcher
Attack Information:
iWonBar
Trojan-Downloader: Win32.Delf.phh 1
Trojan-Downloader: Win32.Delf.phh 2
Trojan-Downloader: Win32.Delf.phh 3
Trojan-Downloader: Win32.Delf.phh 4
VPN-1 VSX NGX R65
How Can I Protect My Network?
1. In the SmartDefense tab, click Web Intelligence > HTTP Protocol Inspection > Header Rejection.
2. In the Header Rejection configuration pane, under Header Rejection Settings > Mode, check Active.
3. Enable the following protections:
iWonBar 1
Trojan-Downloader: Win32.Delf.phh
4. In the SmartDefense tab, click Web Intelligence > Malicious Code > General HTTP Worm Catcher.
5. In the General HTTP Worm Catcher configuration pane, under Settings > Mode, check Active.
6. Enable the following protections:
iWonBar
Trojan-Downloader: Win32.Delf.phh 1
Trojan-Downloader: Win32.Delf.phh 2
Trojan-Downloader: Win32.Delf.phh 3
Trojan-Downloader: Win32.Delf.phh 4
7. Install policy on all modules.
How Do I Know if My Network is Under Attack?
SmartView Tracker will log the following entries:
Attack Name: Header Rejection
Attack Information:
iWonBar 1
Trojan-Downloader: Win32.Delf.phh
Attack Name: HTTP Worm Catcher
Attack Information:
iWonBar
Trojan-Downloader: Win32.Delf.phh 1
Trojan-Downloader: Win32.Delf.phh 2
Trojan-Downloader: Win32.Delf.phh 3
Trojan-Downloader: Win32.Delf.phh 4
InterSpect NGX
How Can I Protect My Network?
1. In the left pane, select Profiles > Default Protection and select the Web Intelligence page of the profile.
2. In the Web Intelligence tree, click HTTP Protocol Inspection > Header Rejection.
3. Enable the following protections:
iWonBar 1
Trojan-Downloader: Win32.Delf.phh
4. In the Web Intelligence tree, click Malicious Code > General HTTP Worm Catcher.
5. Enable the following protections:
iWonBar
Trojan-Downloader: Win32.Delf.phh 1
Trojan-Downloader: Win32.Delf.phh 2
Trojan-Downloader: Win32.Delf.phh 3
Trojan-Downloader: Win32.Delf.phh 4
6. Install policy on all modules.
How Do I Know if My Network is Under Attack?
SmartView Tracker will log the following entries:
Attack Name: Header Rejection
Attack Information:
iWonBar 1
Trojan-Downloader: Win32.Delf.phh
Attack Name: HTTP Worm Catcher
Attack Information:
iWonBar
Trojan-Downloader: Win32.Delf.phh 1
Trojan-Downloader: Win32.Delf.phh 2
Trojan-Downloader: Win32.Delf.phh 3
Trojan-Downloader: Win32.Delf.phh 4