Hi,
this is due to a gross misconfiguration of the AV threshold.
The size limit is not only the setting which triggers the " oversize" warning in the log. It determines up to which filesize content is AV scanned. The reasoning behind this is that malware is mass replicated only in small files. The percentage of infected files drops to 0.1% for filesizes of 2 MB or more. (there is a paper on the analysis of infected files vs. filesize somewhere, I can' t remember it at the moment).
Sometimes the filesize is known in advance, sometimes not (e.g. streams). So, the FG will scan up to the threshold, and if nothing is found, will pass the file/stream unscanned. All files below the threshold are scanned in total.
So, with your setting of 500 MB 100% of your incoming data is scanned which takes a toll on latency and CPU load.
1. Recommended setting for the threshold is 2 or 3 MB. You won' t gain anything beyond this size, on the contrary you' ll waste a lot of system ressources.
2. I would cancel client comforting altogether for security reasons. If the WAN connection is fast enough this won' t make a big difference in latency.
If the 620B wasn' t such a great piece of hardware you would have noticed far earlier.
Ede Kernel panic: Aiee, killing interrupt handler!