Question
IPS killing downloads?
We have a 400A as our primary firewall that is currently running v4.0, build0632, 120705 (MR3 Patch 8). For months (and several FortiOS versions) we' ve have had problems with downloads and web browsing. It was very difficult to track due to a lack of consistency (" The Internet is slow....Waaahhhh!" ). Finally we figured out that exempting sites from IPS resulted in a marked improvement in reliability. It seems that if we have IPS turned on for the policy that governs our users' web browsing, we see a flurry of " deny status" with a message of " no session matched" . Downloads fail to complete, or report that they are complete but files are corrupt of only partially downloaded. We have tried to open a ticket with Fortinet on the issue but could never successfully navigate past level 1 support. If anyone has had a similar challenge I would love to hear how you resolved it.