Skip to main content
Jeff_the_Network_Guy
New Member
August 30, 2012
Question

IPS killing downloads?

  • August 30, 2012
  • 15 replies
  • 17505 views
We have a 400A as our primary firewall that is currently running v4.0, build0632, 120705 (MR3 Patch 8). For months (and several FortiOS versions) we' ve have had problems with downloads and web browsing. It was very difficult to track due to a lack of consistency (" The Internet is slow....Waaahhhh!" ). Finally we figured out that exempting sites from IPS resulted in a marked improvement in reliability. It seems that if we have IPS turned on for the policy that governs our users' web browsing, we see a flurry of " deny status" with a message of " no session matched" . Downloads fail to complete, or report that they are complete but files are corrupt of only partially downloaded. We have tried to open a ticket with Fortinet on the issue but could never successfully navigate past level 1 support. If anyone has had a similar challenge I would love to hear how you resolved it.

    15 replies

    TopJimmy
    New Member
    September 21, 2012
    I too use IPS on outbound policies. I don' t do it to " keep the internet clean" but I do it to protect outbound traffic from vulnerabilities. Example: The latest MS and JAVA vulnerabilities have an IPS signature in the " client" section of the IPS signatures. I apply those to outbound " client" sensors to block any malicious internet hosts from exploiting any potential vulnerable workstations/servers on my network. Maybe I' m missing the boat here but I think it was designed that way otherwise why else would they have a " client" target in the signatures.
    cmberry
    New Member
    September 27, 2012
    I use IPS on Internal > WAN connections too. Actually I use all UTM on outbound connections. I dont see how else you would stop a malicious site from causing havok without it. For instance, at 8am last Friday morning, I went to http://consumerist.com Guess what? They had been hacked and their site was pushing redirects to malicious sites attempting to install all sort of nastiness. Between Fortinet and Eset, nothing got past. Well, within an hour the site had gone down and remains down as of this hour, it was a serious hack. So, if I didnt have outbound UTM turned on, and I intentionlly went to a site I know and trust, how else would I have been protected in a situation like this? I dont understand people recommending only having inbound (e.g. FTP servers, webservers, etc) protected. Am I the dumb one?
    cmberry
    New Member
    September 27, 2012
    OK, I think I have a major update to the whole " Broken Download" problem. It appears to NOT be Fortinet' s problem! (Yes, I am shocked too) I stumbled upon this today, I recommend everyone reading it, even if you dont think you have download issues:
    The recently released KB2735855 has been confirmed to cause data corruption
    http://www.wilderssecurity.com/showthread.php?t=332920 http://answers.microsoft.com/en-us/windows/forum/windows_7-windows_update/kb2735855-causes-my-downloads-to-break/50beff42-60b1-44d3-9c6c-d46e91878bc0 I just uninstalled it, and will report back in 24 hours. I am resonably confident since my symptoms match almost exactly, and have been happening in the exact period since that patch was installed. Hope this helps!
    FG_User
    New Member
    October 2, 2012
    what' s the verdict? any luck?
    Jeff_the_Network_Guy
    New Member
    October 2, 2012
    We' ve been running this update network wide since 9/14 with no change in behavior.
    cmberry
    New Member
    October 5, 2012
    We' ve been running this update network wide since 9/14 with no change in behavior.
    I read that it is possible that this bug only causes issues for people with 4+ CPU cores. (I have 6 cores). Might explain why not everyone has noticed it. Also, there must be some merit to the problem, as MS has announced they are looking into it.
    messalina
    New Member
    November 8, 2012
    Hi guys, me too thinks that it is actually more important to inspect the " outbound" traffic. most of the malware is coded to attack by http return packet stream, like the latest ms and java attacks that would give attacker an administrator level remote connection to infected workstations.