Skip to main content
rashley
New Member
June 6, 2016
Solved

Forticlient - IGMP storms

  • June 6, 2016
  • 3 replies
  • 26745 views

Hi All,

 

We recently started installing the Forticlient due to a virus outbreak that was not caught by Symantec.  On top of the virus, for a week I have been dealing with random IGMP storms on the LAN and I cannot seem to track it down.  I was worried a couple of our servers had something malicious on them that was causing them to send out all this traffic.  It would cripple our server vLAN and it is very random.  Sometimes I can do a day without any storms, but other times it happens an hr or two after rebooting the servers.

 

I did find one post about someone having a broadcast, or multicast storm and it was the Forticlient that seemed to be the culprit.  Has anyone else noticed this type of behavior, especially when installed on a VMware VM?

 

I started installing two new Server 2012 VM's on Friday.  The only thing I installed, aside from Windows updates, was the Forticlient and later on the network was flooded with IGMP traffic again.  It really seems like something with this client causing the storms.  I have ran 3 different antivirus scans on the original servers I was worried about and they came back clean in each scan, so it's got to be something else, like the Forticlient causing some IGMP storms for some reason.

 

Thanks in advance

Ryan

    Best answer by jpplante

    "Block known communcation channels used by attackers" stops Botnet communications and the like.  Its definitely a feature worth having.  I mentioned before the other option I enabled this time was Auto Update.  I am going to test the auto update option without the block all comm option.  

     

    I am hoping its as easy as "turn on feature, problem arises" and not some sort of perfect cocktail situation.  If a single option is causing the issue it will be easy to circumvent and will give Fortinet ammo to find the real issue.

     

     

    3 replies

    Hediin_Rico
    New Member
    June 6, 2016

    Its the forticlient, They wont openly admit to it being the client until you bring it up. PM me for my ticket number that you can reference it.

    jpplante
    New Member
    June 6, 2016

    I am also having this issue.  I have a ticket open.  It is not affecting my Mac OSX systems, only my Windows systems.  It has been known to take down entire segments of my network.  I had this problem when I:

     

    A) turned on Application Control

    B) turned on Auto Update

     

    I have not tried to many other items yet because I have to wait for maintenance windows to test things due to the nature of my outages.

     

    JP

    rashley
    rashleyAuthor
    New Member
    June 6, 2016

    Have they given you any other information as to why it does this?  Seems like a pretty serious bug.  It took down our server segment a number of times because I could not trace what the actually issue was.

     

    I'm now in the process of removing Forticlient on the servers and going back to Symantec to test and see if these flooding issues go away

    rashley
    rashleyAuthor
    New Member
    June 7, 2016

    Interesting.  Thanks for the info.  What exactly does the Block known communication channels do?  I also have that enabled for the client workstations, so I'm a bit worried they might start a broadcast storm.

    lokean13
    New Member
    August 22, 2016

    I really wish this had been a thread that I would have seen last January when my network was getting constant floods and I couldn't figure it out.  It was FCT that whole time.  I "fixed" it by turning Multicasting off on the printers and setting up vlans, but wish I would have found this out.