Skip to main content
Jeff_the_Network_Guy
New Member
August 30, 2012
Question

IPS killing downloads?

  • August 30, 2012
  • 15 replies
  • 17489 views
We have a 400A as our primary firewall that is currently running v4.0, build0632, 120705 (MR3 Patch 8). For months (and several FortiOS versions) we' ve have had problems with downloads and web browsing. It was very difficult to track due to a lack of consistency (" The Internet is slow....Waaahhhh!" ). Finally we figured out that exempting sites from IPS resulted in a marked improvement in reliability. It seems that if we have IPS turned on for the policy that governs our users' web browsing, we see a flurry of " deny status" with a message of " no session matched" . Downloads fail to complete, or report that they are complete but files are corrupt of only partially downloaded. We have tried to open a ticket with Fortinet on the issue but could never successfully navigate past level 1 support. If anyone has had a similar challenge I would love to hear how you resolved it.

    15 replies

    rwpatterson
    New Member
    August 30, 2012
    Just what (to me) appears to be a silly question. Why would you want to protect outbound traffic? Trying to keep the Internet clean?
    jtfinley
    New Member
    September 4, 2012
    Bob - Funny you say that, but I too have done this. Placing an IPS on an internal - > WAN connection only to see the internal users get blocked, etc. Live & learn.
    JaapHoetmer
    New Member
    September 5, 2012
    Hi Jeff. I have experienced a similar situation with a relatively new FG40C, loads and loads of errors logged showing ' no session matched' for a variety of outbound protocols, a very slow internet access, and difficulty accessing the Web GUI. I have tried a lot to analyse the issue, and finally found out that the physical LAN port #1 is probably faulty. After switching the cable that was plugged into port 1 over to port 5 on the FG40C, the errors disappeared and access returned to normal. It may not be the same issue you are experiencing, but it does point to issues in the physical world, maybe cabling? I am now in contact with the supplier, if I find out more I will let you know. Cheers, Jaap
    Jeff_the_Network_Guy
    New Member
    September 7, 2012
    Interesting. I' ll keep that in mind. I had a lot of problems with sites my Accounting group used to process payments. They' d get kicked out of sessions, or pages would not load. I ended up exempting the sites from IPS checking, and that kept them from having problems anymore. So far for me, this seems to be a challenges that results directly from the application of IPS to the rules. The results have been night and day when I enable/disable IPS.
    Coldfirex
    New Member
    September 6, 2012
    So do you ever have IPS on outbound policies? We have been doing this way (including for incoming traffic policies) with no major issues. My understanding was that this would help for example if a client connects to a remote server (web, email, etc) that itself might be infected or doing something malicious that IPS would prevent.
    Jeff_the_Network_Guy
    New Member
    September 7, 2012
    Maybe I' m reading things wrong but all of my " outbound" policies have IPS on them. Wouldn' t you want to check the stream of your user' s HTTP traffic for anomalies that might target them? I know the initial idea of network security is keeping hackers out, but considering how many exploits are payloaded into normal download traffic it seems to me that you had better be checking everything. The data brought in due to an HTTP get request from a user' s PC is not governed by an " inbound" firewall policy.
    SOLID_SYSTEMS
    New Member
    September 9, 2012
    Interesting, I' ll be going for my training next week and this will be my first exposure to fortinet. I come from a cisco heavy background and have been wondering if the transition to fortinet will be a bumpy ride.
    Secure_IT_BE_Nick
    New Member
    September 10, 2012
    So why 2 different targets then?? And a default IPS profile protect_clients? Ofcourse you use IPS for internal --> wan policies. For Jef' s problem changing the ips to flow instead of proxy could help with the performance or play with the protocol options.
    Jeff_the_Network_Guy
    New Member
    September 12, 2012
    I am not sure about the flow versus Proxy setting for IPS. Is that the same as " set algorithm low" under " config IPS global" ? My " General" IPS setting for most of the company is Windows, Client, High, Critical, IM, HTTP, FTP, RTSP, Oracle, IE, MediaPlayer, MSOffice, Adobe, Sun, IM. I' d like to think that is pretty well defined down, but it still gets me 1215 possibilities.
    ejhardin
    New Member
    September 10, 2012
    Jeff, I' m wondering what your IPS policy looks like for your outbound traffic? Also check out my post on Old IPS Signatures. http://support.fortinet.com/forum/tm.asp?m=88509&p=1&tmode=1&smode=1
    ejhardin
    New Member
    September 12, 2012
    Nick and Jeff, IPS doesn' t have a flow or proxy setting. IPS is flow. Jeff, The " set algorithm low setting" is a performance enhancement setting. Setting it to low will use less memory but will be less accurate.
    cmberry
    New Member
    September 14, 2012
    my downloads are being killed too. May or may not be related to the fact the youtube videos, quicktime videos, etc, all only partially download /stream. I had to download an update for adobe lightroom 8 times today to get 1 to go to completion. Also had several other web downloads start and not finish. I have IPS turned on, but have not tried yet to pinpoint if IPS causes my issues. I have seen this behaviour on my 200b, running both 4.3.9 and 4.3.10.
    Jeff_the_Network_Guy
    New Member
    September 17, 2012
    Hey cmberry, are you using traffic shaping? I am starting to wonder if this could be part of the equation. I have a client we have to download PDF files from that has been giving us problems for months. Recently I added the download server to our IPS exemption list, but the half downloads are still happening. I am starting to wonder if the traffic shape I have in place to keep using from using the pipe is resulting in the incomplete downloads instead of the IPS checks. Just a thought.
    cmberry
    New Member
    September 20, 2012
    Hey cmberry, are you using traffic shaping? I am starting to wonder if this could be part of the equation.
    I dont use traffic shapping, but I do use ECMP routing. I have a call into the reseller to see if they can help me track this problem down. I' ll post any updates.