Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Not applicable

FTP Files Problem

I' m having a weird problem with FTP. If I send a file using a client like Filezilla it will send the file over to an FTP server without a problem. However if I send the file over via windows command line ftp it will send the file short some bits. Example if I send putty.exe 454,656 filesize ... when it' s done sending to the ftp server I will have a file with the size of 453,598 on the server. Something is shaving my files off when I send by command line. The files are not getting logged a viruses. Any thoughts?
14 REPLIES 14
Not applicable

yeah ... thats been my solution while troubleshooting this.
Victor
New Contributor III

Dirk: I cannot completely address the anomalies of AV & IPS. We tried implementing them but found with our large site (20K computers) that the fortigates just couldn' t handle it. Being an educational institution to boot, the students tend to kick the tires much more then corporate or institutional clients. However, even with an av/ips free active profile list, the av & ips engines are running. They are what inspects the packets cached by the proxy service (thttp) and enforce the policies you have in place. You might want to check " diag sys top 1" and see how those services are running. If they are pegged the issue may be there. I have done some dos based ftp but not through the the fortigates. Just as a test, I used ftp to get putty from simon' s site & my files matched. I would suggest, if you have a support contract, that you open a call ticket. Victor P.S.: If you do implement AV, take the default file size of 10 and reduce it to 4 or lower on any of the protocols that you' ve activated. How many viruses/worms/trojans do you know that have sizes in the mb range?
Not applicable

Thanks Victor. Those processes are running fine. Max of 19 at any point in time. Just curious, in your environment what model Fortigate did you find incapable of handling those security layers? If not Fortinet what are you using?
Victor
New Contributor III

We have two 3600s in HA (A-P). We had had them in A-A but stability was an issue and if you' ve had any experience doing a packet trace in that mode you' ve probably wished you were an Indian god (or should I say, goddess) and could' ve used those extra hands to handle all the putty sessions. As for how we handle without, we have other monitoring and IDS devices that monitor the flows at different stages in our networks. Fortinet has said that these 3600s should be able to handle our flows (between 125mbps to 140mbps during school hours) but it is not our experience when we add the additional services. Victor
Not applicable

For closure ... this turned out to be a hardware problem. Fortinet RMA' d me a new rig and to my surprise it works now.
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors