Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Phuoc_Ngo
New Contributor

Enable Antivirus scanning cause a major performance backdrop

Had anyone experience a sluggish performance when enabling Antivirus scan under protection setting? Every single time we enable antivirus scan, the firewall throughput perform is degraded 90% and stay at the max throughput all the times. We only have one Antivirus scanning policy enable as a test.
15 REPLIES 15
TopJimmy
New Contributor

which hardware and FortiOS version are you on? I' ve got all the units in my signature and all of them have AV enable and performance has not taken a hit on any of them.
-TJ
-TJ
Not applicable

Does anyone know why Fortinet Client antivirus, used in standalone mode (not as remote enterprise desktop) would suddenly start causing huge web performance degradation? I' ve been using it for more than a year, and suddenly 2-3 months ago it started really slowing things down. I call up a web page, and the page appears right away, but the page doesn' t respond--scroll bars, etc.--for 10 to 15 seconds. When I disable the Fortinet client, the problem goes away. Did Fortinet do something to their software recently to cause this? I can' t seem to find any settings I can change to try and counter the problem. It is also taking very long to upload photographs. Often the session times out before the upload finishes. Is Fortinet assuming I am in an enterprise environment, and scanning things on the way OUT of my computer? And if so, is there a way to make the software stop doing this? I am running Windows Vista, and have a 10Mbps cable modem connection. Any assistance is greatly appreciated!
Not applicable

I am having some of the same issues. We are running an HA pair A-P of 620B' s. When we turned on Anti-virus the network slowed way down. I have users complaining all over the place about webpages failing to load or taking several minutes. I was able to test a box using the protection profile and one unfiltered and the difference is tremendous. We are not using the fortigate client software which is different from your comments.
Not applicable

Broadbrook, I am having the same problem. I remove the http option in Protection Profile/AV (im using the scan profile name) the problem goes away.. any technical help or recomendation would be great... db
abelio

any technical help or recomendation would be great...
Did you try lowering the buffering setting? Avoid to buffering 10MB to scan viruses help in a lot of situations

regards




/ Abel

regards / Abel
Phuoc_Ngo
New Contributor

We have a cluster of Fortigate 500 running 3.00-b0741 (MR7 P5). We also lower the buffer setting as suggested but the performance hit still there. Also once we lower the buffer setting down to 1 and 1024. We don' t seem to catch any virus at all. We tested by accessing to known trojan horse site and also sending 50 virus email to internal and it all went through. Any suggestion?
abelio

We don' t seem to catch any virus at all.
then something is wrong or missing in the conf; recheck that profile with AV filtering is applied to the relevant firewall policy you' re testing (in/ out traffic origin etc) If you test any special port different from standard ones, i mean, HTTP std port is 80, but if your proxying http traffic with for instance, port 81, AV will became blind for that. You' ll need to adjust AV settings for that kind of things.

regards




/ Abel

regards / Abel
Not applicable

Thanks for the replies abelio & Phuoc. I changed the suggested setting to 1 - 600 based on this article http://tinyurl.com/njfn9w However, I noticed that the download was still taking longer so I configured the setting to be 1 – 1200; this seems to fix the issue. Phuoc brought up a great point, how do I know if the HTTP scan is working at all with the applied settings I have. Anyone know a known Trojan horse sites? Any Suggestions
abelio

Anyone know a known Trojan horse sites? Any Suggestions
Play with some porn sites, you' ll get plenty of trojans after a while, and some fun.. advice: use a destroyable virtual machine logged with an account with no administrative privileges.

regards




/ Abel

regards / Abel
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors