Skip to main content
Contributor III
May 9, 2008
Question

FTP Files Problem

  • May 9, 2008
  • 14 replies
  • 6267 views
I' m having a weird problem with FTP. If I send a file using a client like Filezilla it will send the file over to an FTP server without a problem. However if I send the file over via windows command line ftp it will send the file short some bits. Example if I send putty.exe 454,656 filesize ... when it' s done sending to the ftp server I will have a file with the size of 453,598 on the server. Something is shaving my files off when I send by command line. The files are not getting logged a viruses. Any thoughts?

    14 replies

    abelio
    SuperUser
    SuperUser
    May 10, 2008
    It smells like a cache somewhere giving a broken version file of putty.exe.. Not FTG because Filezilla use the same firewall policy and transfer ok. Verify checksum of putty.exe file to confirm the broken binary.
    Contributor III
    May 10, 2008
    I' ve confirmed this problem with several different file with the same result as the example. Weird huh?
    Contributor III
    June 2, 2008
    Sorry, I picked this up a bit late. I think you problem here may be caused by your use of the Windows FTP client not the FortiGate. By default, it starts in ASCII not Binary mode and will break any binary file transfer. Try the following: >ftp ftp.yoursite.com User: <username> Pass: ********* >bi >hash >get filename.exe This should result in a complete transfer. Let us know Carl
    Contributor III
    June 2, 2008
    Same thing. If I ftp through the Unfiltered protection profile I get " Connection closed by remote host." after most of the file gets sent. If I run through a policy without any protection profile it goes fine.
    rwpatterson
    New Member
    June 2, 2008
    Perhaps FTP client comfort settings?
    Contributor III
    June 2, 2008
    Have you seen this apply if the FTP protocol is not even selected in the protection profile? Looking at the unfiltered profile I see that Interval is 10 and Amount is 1. I' ll try playing with those. Any recommendations? Thanks.
    rwpatterson
    New Member
    June 2, 2008
    If it' s not selected, then the A/V will read the entire file before passing it. Could be your issue. Leave the settings as they are, and check the FTP box...see what happens.
    Contributor III
    June 2, 2008
    Selecting FTP under AV fixed it. I didnt want to apply the AV layer at the point this is deployed. So the questions are: 1) Why is this causing the file transfer to fail? 2) Why is it scanning AV if it' s not configured in the Protection Profile? 3) Would this apply to other protocols in AV?
    rwpatterson
    New Member
    June 2, 2008
    Create a policy for FTP alone, and skip the PP... Don' t have the answers, but a temporary solution.
    Contributor III
    June 2, 2008
    yeah ... thats been my solution while troubleshooting this.
    Victor
    New Member
    June 3, 2008
    Dirk: I cannot completely address the anomalies of AV & IPS. We tried implementing them but found with our large site (20K computers) that the fortigates just couldn' t handle it. Being an educational institution to boot, the students tend to kick the tires much more then corporate or institutional clients. However, even with an av/ips free active profile list, the av & ips engines are running. They are what inspects the packets cached by the proxy service (thttp) and enforce the policies you have in place. You might want to check " diag sys top 1" and see how those services are running. If they are pegged the issue may be there. I have done some dos based ftp but not through the the fortigates. Just as a test, I used ftp to get putty from simon' s site & my files matched. I would suggest, if you have a support contract, that you open a call ticket. Victor P.S.: If you do implement AV, take the default file size of 10 and reduce it to 4 or lower on any of the protocols that you' ve activated. How many viruses/worms/trojans do you know that have sizes in the mb range?
    Contributor III
    June 4, 2008
    Thanks Victor. Those processes are running fine. Max of 19 at any point in time. Just curious, in your environment what model Fortigate did you find incapable of handling those security layers? If not Fortinet what are you using?
    Victor
    New Member
    June 6, 2008
    We have two 3600s in HA (A-P). We had had them in A-A but stability was an issue and if you' ve had any experience doing a packet trace in that mode you' ve probably wished you were an Indian god (or should I say, goddess) and could' ve used those extra hands to handle all the putty sessions. As for how we handle without, we have other monitoring and IDS devices that monitor the flows at different stages in our networks. Fortinet has said that these 3600s should be able to handle our flows (between 125mbps to 140mbps during school hours) but it is not our experience when we add the additional services. Victor
    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!