Skip to main content
Contributor III
March 12, 2004
Question

FG-60 Stops Passing Traffic

  • March 12, 2004
  • 35 replies
  • 11437 views
I' m at my wits end and I' m hoping you guys can help out with a problem that I' ve got. We have deployed a couple of FG-60s and are now having problems with the devices. The first sign of trouble was when a client complained of not having Internet access (port 80). We were running MR-6 at the time. If I reset the device traffic would start to flow again. After this happened a couple of time, I called the support number for assistance. I was asked to upgrade to MR-7 which I did. We then started having occasional problems at the same client with POP3 access. Again, a reset on the device cleared the matter. Today, we experienced problems at our colo site (big problems here) with accepting POP3 traffice on an FG-60 with MR-6 installed. It' s not like we' re lighting up the devices with activity but I cannot continue resetting the devices to get things going again. It appears that the device just stops accepting/forwarding traffic. Does anyone have any ideas abou what' s happening?? I' m ready to pull the devices and install something that won' t fail in this manner. Any help is appreciated.

    35 replies

    Contributor III
    March 13, 2004
    You’re not the only one that is getting pissed off with this. I was having major problems running 3 POP3 servers behind the firewall, service just stopped working. MR7 seemed to cure the problem but now my HTTP server is suffering… We are being attacked all the time, I was using a Guardian firewall, this worked fine just had port routing limitations… I am seriously considering in putting the Guardian back on line and using the Fortigate as a door stop… Regards, Kevin Vahn Gill Ring Communications (UK) Ltd
    Contributor III
    March 15, 2004
    Hi All, Sorry to say this but I take comfort in knowing that I am not the only one… Last night, (23:20) my HTTP server went off air and we started to get NetSky on internal mail… The firewall had decided that I longer needed to scan SMTP for viruses and that I didn’t need a web server… Back to Guardian and Total Virus Defence me thinks... Regards, Kevin…
    SECCON1MC
    New Member
    March 14, 2004
    We have had the same issues with a FGT-50 with MR6 with web traffic and when av scanning is enabled.. The kicker is that it only stops working at our client' s site after 2-4 days (they have very low use of the web). If we disable AV.. all is fine. It sounds like a memory/session issue that the fortiCODERS need to clean up. The only fix I can think of is going back to OS 2.36 (whichs needs to be tftp' ed) Good luck.
    Contributor III
    March 15, 2004
    [Deleted by Admins]
    Contributor III
    March 15, 2004
    So, let me get this straight: 1. I should not use MR7 because it' s buggy 2. I need to disable all NIDS 3. I need to disable all AV scanning Hmm, not much of a firewall is it? The only thing it' s doing is port-forwarding to a private internal network for security. Netgear, Linksys, et. al. provide this level of service at less than half the price!
    Contributor III
    March 15, 2004
    [Deleted by Admins]
    Contributor III
    March 15, 2004
    [Deleted by Admins]
    Contributor III
    March 15, 2004
    Hi All, I will let you know how I get on with this but we are upgrading to a FG200... Not quite the best solution to the problem (£££) but it may work... Regards, Kevin...
    Contributor III
    March 15, 2004
    What gives you any level of confidence that moving to a 200 will solve this problem? It seems to me that there is a fundamental flaw in the scanning engines which can lead to ultimately losing HTTP/POP3/IMAP/whatever.
    Contributor III
    March 15, 2004
    From what I understand is that this problem may be due to Memory / CPU usage... The FG200 has a 20GB hard drive and greater connection capacity... I wouldn’t say that I have confidence in upgrading to the FG200 but I would like to believe that doing so will cure the problem. (I’m not religious but I am praying) NIDS & Anti virus is important and I must have them both running. I have on average 6000 hits per hour on my main web server & forward around 5500 emails per day through any one of three SMTP servers. We have around 1000 clients who use short TCP connections (300 Bytes) connecting every 240 seconds to some custom software. It seems that the above is just too much for the FG-60 causing an average 75% memory & CPU load. Switching off the NIDS or Anti virus is not really an option (Although I still intend to run additional anti virus internally) Regards, Kevin...
    Contributor III
    March 15, 2004
    40-gaters, this is bad, bad news for me. I experienced that problem since december 2003 with a FGT-50R and was suggested to do a boot media format. After that, the problem' s temporarily gone, but other problems occured. MR6, not higher, not even tried MR7. And I was told the memory on the FGT-50 is much more limited on FW 2.50 as it was on 2.36. And possibly no 2.80 Ok, I decided to move to a FGT-60, but now...... What' s the right way if we don' t have the money|need for a FGT-200? What if only 2-4 users are behind the wall and the main purpose is to have NIDS and AV running, along with VPN and a few policies? I have been that happy when I first get my FGT-50 - and now all enthusiasm has been gone, along with the reliability.... Bad bad news today.... Michael
    Contributor III
    March 17, 2004
    Michael, Whats the amount of users etc. that you are having behind the FG environment and what applications are you looking at running on the FG? We have some 50 FG50 & FG60 running in all kinds of configs and I could give you a rule of thumb before your bad bad day goes bad bad bad
    Contributor III
    March 18, 2004
    Soeren, I don' t have many users behind the device, but after sending my config to FortiGate support, they told me to have possibly too less memory for my needs. I' m using many features, primarily policies, AV and NIDS, along with extensive logging and HTTP/POP3/SMTP scanning features. And I' m using 2.50/MR6. 2.80 wouldn' t be supported, I guess, due to the lack of memory. They also suggested me to switch some features off that I don' t really need, but why should I purchase a FortiGate if I can' t use all of its features altogether? So switching to a FG-60 seemed to be the way... until I read these postings. Michael
    Contributor III
    March 16, 2004
    I have two FG-300' s that are on MR7 and not experiencing any problems passing traffic.
    Contributor III
    March 17, 2004
    [Deleted by Admins]
    skyhigh
    New Member
    April 6, 2004
    ORIGINAL: slayer I hope Fortinet people are reading all our posts and hope they shed light to some of our questions... it seems like we' re the only onces answering questions.
    Reading ... yes. Answering questions ... rarely. This is a user forum. If you have a technical support question for Fortinet technical support, please open a ticket with us through the normal channels (e-mail or phone).
    Contributor III
    April 6, 2004
    WHAT???
    Contributor III
    March 18, 2004
    Hi All, Initial testing of the FG200 has proven very interesting: Approximately 50% of my service traffic is now being passed through the FG200. It’s hardly registering on the CPU usage…!!! Internal -> External performance is lightning speed…!!! (Better than I ever got on the FG60) I shall be moving the remainder of my services over tonight and will let you know how it goes… Regards, Kevin…
    Contributor III
    March 20, 2004
    Hello All, (Again) My FG200 is now fully installed and it’s working perfectly… Average CPU / Memory usage is less than 25%; the performance is outstanding to the point that I have received calls from several of my customers who have noticed the difference. Alex mentioned in an earlier post that the FG200 supported 802.1q VLANs… In my original specification I needed 3 local networks and was therefore considering the FG400 but the price was just too high. I have an old 3Com 3300 switch that was mothballed (noisy fans) I reconfigured this for 3 VLANs, connected it to the DMZ port and it works a treat… All in all it looks like the best solution for me was to upgrade to the FG200 however, on specification, the FG60 should have done the job. It is my opinion that too many features are available on the FG60 and the CPU / Memory configuration is just not up to the job, especially if you are providing services behind the firewall. The FG60 may well be perfect as an office connectivity router but not if you need to run any services. One other comment, I am using SSH Sentinel for VPN access through the firewall, with only one client connecting through the FG60 it was slow and not that reliable, through the FG200 there is virtually no degradation in performance and so far it has connected every time. I would like to thank every contributor to this forum and hope that you all find a solution to this problem. All of your comments have helped me to resolve the problems here. Many Thanks to you all, Regards, Kevin Vahn Gill
    Contributor III
    March 25, 2004
    Kevin, I was wondering how many users you have going through the FG-200 and what services you have lit up. I am asking because I have run into problems scanning inbound HTTP traffic with the session starting from the user. Spikes the CPU usage in the FG-100 and now I have seen it happen again in a FG-1000 demo I am doing. Thanks
    Contributor III
    March 25, 2004
    Hi Scott, Internal Users = 6 Servers & 5 Workstations. Server 1 = (HTTP, FTP, SMTP & POP3) Server 2 = (HTTP, FTP, SMTP & POP3) Server 3 = (Jabber & FTP) Server 4 = (HTTP, FTP & 2 Custom Services) Server 5 = (SMPT, POP3 & Jabber) Server 6 = (12 Custom Services) Server 1 & 2 average 6000 web hits/hour each (24hrs) Server 1 & 5 average 3000 total emails per day (8am – 6pm) NDIS Enabled on External Interface AV Enabled on ALL Incoming Traffic Using Port Forwarding on all services, only about 12 public IP’s in use. Running 3 VLANS on DMZ Interface via 3Com 3300 Switch Average CPU ~ 24% & Average Memory ~32% Sessions usually between 200 & 600 on 5 second update… ALL (YES ALL) of the problems I had with the FG60 have gone completely. It got to the stage that I was having to reboot the unit 1-2 times a day, 3 times in one week I had to reboot it in the early hours (2am – 4am, I was not happy) The 3 VLANS are test only so their is hardly any traffic on them, During the day only one workstation is in use, mine… when the kids get home then they start using some bandwidth. Hope that helps, any questions please don’t hesitate to contact me. Regards, Kevin… Email: Kevin@gillns.com
    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!