Skip to main content
ISOffice
New Member
August 9, 2018
Question

Windows Update - Files Blocked

  • August 9, 2018
  • 5 replies
  • 43228 views

Hi all,

 

We have 2 X 100D Hardware Appliances running firmware version 6.0.1 (build 0131 GA) in NAT (Flow-based) Mode (HA: Active-Passive).

Recently I have noticed that in the GUI under Log & Report > AntiVirus, there has been an upsurge in files being blocked by the FortiGates. As they are mostly .cab files originating from Microsoft I'm working on the assumption that they are related to clients laptops on our wireless network attempting to update via Windows Update.

No explanation is given in the logs, other than the file was blocked as it was "infected". We are not running deep inspection on our Internet traffic and as these were HTTP requests I don't think SSL/SSH Inspection is interfering here.

Could someone please shine a light on what the issue may be here and how I can resolve it?

Many thanks for your kind assistance.

 

Best regards,

 

John P

    5 replies

    bonafide
    New Member
    August 11, 2018

    I'm seeing alert messages similar to what John is describing.  Here is the email version:

    Message meets Alert condition
    Virus/Worm detected:  Protocol: "HTTP" Source IP: 192.168.2.6
    Destination IP: 205.185.216.42 Email Address From:  Email Address
    To:  VIRUS REFERENCE URL:
    date=2018-08-11 time=00:10:10 devname=gate devid=FGT60E4Q16081196 logid="0211008192" type="utm" subtype="virus" eventtype="infected" level="warning" vd="root" eventtime=1533964210 msg="File is infected." action="blocked" service="HTTP" sessionid=9218949 srcip=192.168.2.6 dstip=205.185.216.42 srcport=61551 dstport=80 srcintf="Office LAN" srcintfrole="lan" dstintf="wan1" dstintfrole="wan" policyid=10 proto=6 direction="incoming" filename="26979962_4691678f40c
    59e48a351077614b886df9327d506.cab" quarskip="File-was-not-quarantined." url="http://download.windowsupdate.com/c/msdownload/update/others/2018/07/26979962_4691678f40c59e48a351077614b886df9327d506.cab" profile="default" agent="Windows-Update-Agent/7.9.9600.18970" analyticscksum="9dba2305680792c5095394ae42986ee188391b3963aeef992a310c91a3826abb" analyticssubmit="false" crscore=50 crlevel="critical"

    The log alerts appear to be on the same file and are repeating once per hour.  Fortigate logs this with Virus Threat Score 50 (Critical). I've uploaded this URL/File to FortiGuard Labs online scanner, VirusTotal, Scanthis.net and Kaspersky; All indicate the file is clean.

     

    I'm a bit hesitant to bypass the fortigate alert.  Any recommendations?

     

    Thanks,

    Eric

     

    ISOffice
    ISOfficeAuthor
    New Member
    August 13, 2018

    Hi Eric,

     

    Many thanks for your input. I have raised a ticket with Fortinet in regards to this issue and will post any further developments/solutions they suggest.

     

    Best regards,

     

    John P

    ISOffice
    ISOfficeAuthor
    New Member
    August 13, 2018

    Hi Eric,

     

    Fortinet Support (thanks Paul) suggested an upgrade to v6.0.2. The release notes for this version mentioned a bug [ID 497371 - Flow-AV blocks Windows Updates (.cab files)] which has now been resolved. I assume there must have been an issue with the anti-virus scanning engine which created 'false-positives' on .cab file extensions.

    I have now upgraded our appliances to v6.0.2 and will monitor the situation over the next few days to ensure the problem has been sorted.

     

    Best regards,

     

    John P

    Boone
    New Member
    August 13, 2018

    Which Antivirus are you using? 

    ISOffice
    ISOfficeAuthor
    New Member
    August 13, 2018

    Hi Boone,

     

    Our appliances are licensed to receive AntiVirus Updates from FortiGuard (currently using AV Definitions v61.00429).

     

    I'm still seeing .cab files being blocked by our appliances. The reason for this has changed though. When on v6.0.1, the files were blocked as they were deemed "infected". Now, using v6.0.2, the reason has changed to "File reached uncompressed size limit".

    My understanding of the AntiVirus scanning process led me to believe that any files over the default limit of 10MB could not be scanned and would be passed nevertheless without scanning. Therefore I cannot understand why these files are still being blocked.

    I think I'm right in thinking that the scanning limit can be raised using the "config firewall profile-protocol-options > edit 'default' > config http > set uncompressed-oversize-limit" command in CLI. Currently it is set to the default value of 10. I can change this parameter if need be, but I'm still confused as to why the files are being blocked when they should be passed through as they are too big to scan.

    I've passed on my findings to Fortinet support and will post any further developments.

     

    Best regards

     

    John P

    bonafide
    New Member
    August 13, 2018

    @JohnP ... just upgraded form 6.0.1 to 6.0.2 and will be watching the logs. 

    Thanks.

    heisenberg
    New Member
    August 28, 2018

    Hi,

    quite the same issue here (on 6.02 version).

    I have noticed this: "File reached uncompressed size limit" error.

    Unfortunately there not seems to be the parameter to be set in the policy like the old firmware version (that had the "set uncompfilelimit xx").

    Another bad news on this very buggy version.

    No solution for me for now (unless you do not turn off antivirus on that policy)

    ISOffice
    ISOfficeAuthor
    New Member
    August 28, 2018

    Hi Heisenberg,

     

    What IPS Engine Version are you running? Fortinet Support supplied me with v4.00022 (we were running v4.00021 when this issue first occurred) and the issue now seems resolved. Cab files are now being 'let' through the firewalll. I don't think changing the uncompressed file size limit will make any difference if you are still on the old IPS Engine Version. We were still seeing files blocked that were in excess of 10MB.

     

    John P

    heisenberg
    New Member
    August 29, 2018

    Hi,

    I have opened a case and at the end I was given the IPS engine 4.00203 for manual update (Previously I had the same ips version you stated)

    They even said this issue will be fixed in the next "upcoming" 6.0.3GA

    Files (not only .cab) that were "blocked" previously are now "monitored" and flows correctly.

     

    mlines
    New Member
    September 1, 2018

    I am having the same use - a cab update from Microsoft is being blocked for being too large, however I cannot find any option in my 6.02 FortiOS to change it or disable blocking by file size. Any ideas?

    heisenberg
    New Member
    September 1, 2018
    You need the upgraded ips engine from the support or wait until october or disable antivirus. No way to solve in different way
    mlines
    New Member
    September 1, 2018

    Are you saying that disabling IPS (but keeping AV) on a policy will solve this?

    syscom
    New Member
    September 18, 2018

    This issue started for me very recently, can't put my finger on exactly when but within the past few weeks.

    On my end this issue was specific to patching Windows 7 workstations.

    FortiAnalyzer flushed out the blocked traffic.

    To get around this I added a web filter rule:

    URL:  *.windowsupdate.com/*

    Type:  Wildcard

    Action: Exempt

     

    Adding that rule fixed this issue in my environment.

    I have to assume that Windows 7 updates are now failing AV inspection?

    Ashik_Sheik
    New Member
    September 18, 2018

    Specifying action as "Allow" in the URL filter may not allow the URL access. This is because, any attempt to access a URL that matches a URL pattern with an allow action is permitted. The traffic is passed to the remaining antivirus proxy operations, including FortiGuard Web Filter, web content filter, web script filters, and antivirus scanning which may block the url access. Hence, setting the action as exempt allows URL access. However, specifying action as "Exempt” for a URL in web site bypasses following security services - activex-java-cookie - ActiveX, Java, and cookie filtering. av                  - Antivirus filtering. dlp                 - DLP scanning. filepattern         - File pattern matching. fortiguard          - FortiGuard web filtering. pass                - Pass single connection from all. range-block         - Exempt range block feature. web-content         - Web filter content matching.

    syscom
    New Member
    September 18, 2018

    Fresh eyes this morning.

    Looking more closely at the FortiAnalyzer details it is obvious that the issue is with the file size.