Skip to main content
czadbastian
Explorer
August 3, 2023
Question

Fortigate closes wetransfer connections

  • August 3, 2023
  • 15 replies
  • 8610 views

Hello,

 

Fortigate closes connections for reasons unknown to me. I have Fortigate 100F 7.2.3 build 1262. 

 

I applied https://community.fortinet.com/t5/Support-Forum/Large-transfer-fails-becuase-sessions-keep-getting-dropped/m-p/244148 and conserve is off. All policies are proxy based.

 

Anyone know something?

Regards

 

 

 

15 replies

jhussain_FTNT
Staff
Staff
August 4, 2023

Hi,

Do you have any UTMs configured in the policy?

Please test by setting the policy to be flow-based and see if you were successful in uploading the large file.

 

Regards

Jamal

czadbastian
Explorer
August 4, 2023

Hi, unfortunately not

Contributor III
August 4, 2023

Hi @czadbastian

 

Please check the session-ttl value in the established session list

dia sys session filter src <src machine ip>
dia sys session filter dst <destination_ip>
dia sys session list

 

You can adjust based on the session uptime requirement.


- globally in
config system session-ttl
and
- per policy in
config firewall policy
   set session-ttl


Regards

Priyanka

 

- Have you found a solution? Then give your helper a "Kudos" and mark the solution.

knagaraju
Staff
Staff
August 4, 2023

Hi czadbastian,
As you have not enabled any security profiles on the fortigate, it will be acting as a normal L-3 device.

Could you please check the below things
1. Logs&Reports >>forward traffic >> Click on any one of the logs to see the action during the time of the issue.
2. Please check if you have applied any traffic shaping policies.

3.  If you have multiple ISPs connected to fortigate then 
Please route the traffic through other ISP just for testing and check the result.
5. If in case, you are using SDWAN then make sure you have a seperate rule configured to this specific traffic through only one ISP.

Regards
Nagaraju.

czadbastian
Explorer
August 4, 2023

the person with the problem has the rule over the one who is blocking. I have one ISP. I turned off traffic shaping. will see what will happen

czadbastian
Explorer
August 4, 2023

app control and web filter were blocking. In security events it was seen that the web filter was blocking sharepoint services which is strange. Surely fortigate has a problem with filtering traffic to and from sharepoint because in the app control I added everything related to microsoft 365 and there was still a problem. Web filter had defined what to cut but certainly not sharepoint. Just like wetransfer

knagaraju
Staff
Staff
August 4, 2023

Hello czadbastian,

You can try configuring a separate firewall policy using ISDB for wetransfer,just for testing.
Quick note: Please disable all security profiles while creating the ISDB policy.

Please refer the below link for example
https://docs.fortinet.com/document/fortigate/6.2.15/cookbook/179236/using-internet-service-in-policy

Regards
Nagaraju.

czadbastian
Explorer
August 4, 2023

I did this policy. i added wetransfer as fqdn. I found the server addresses somewhere on the s3.amazonaws.com forums
wetransfer.com
wetransfer.net.
And unfortunately it did nothing

Contributor III
August 4, 2023

Hi @czadbastian 

 

I am glad to know that is started working now.

It depends on the hosted server's dependency and redirections. If you want to check more regarding a website access redirection you can check from the browser by using the developer tool

https://support.google.com/admanager/answer/10358597?hl=en

 

FortiGate will look for a matching policy, beginning at the top. Usually, you should put more specific policies at the top; otherwise, more general policies will match the traffic first, and your more granular policies will never be applied. Once a policy is matched it does not look for the other policy. In case when you try to access a website and it has the other domain dependency which is blocked in the bottom rules it will not work as expected. 

 

Regards

Priyanka

- Have you found a solution? Then give your helper a "Kudos" and mark the solution.

czadbastian
Explorer
August 4, 2023

Thank you very much for your help. I know that the rule that is supposed to specify has to be at the top. Regards

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!