Hello there,
We are having issues on machines trying to update to the last windows 11 update 24h2.
The updates are taking way too long, some of them taking 5 hours to complete. Our machines all have SSDs installed, so, don't think it is an I/O issue.
We tested machines without forticlient and they finished updating in about 10 minutes.
Our forticlient versions are 7.2.4.0972 and 7.2.5.1053 (tested in both of them and the issue persists).
I tried disabling Cloud based protection and refining antivirus exclusions, to no avail. Exclusions are as follows:
Paths:
%windir%\SoftwareDistribution\Datastore
%systemroot%\System32\Spool
Files:
%windir%\Security\Database\*.log
%windir%\Security\Database\*.sdb
%windir%\SoftwareDistribution\Datastore\Logs\Edb.chk
%windir%\SoftwareDistribution\Datastore\Logs\Tmp.edb
%windir%\Security\Database\*.chk
%windir%\Security\Database\*.jrs
%windir%\Security\Database\*.csv
%windir%\Security\Database\*.edb
%windir%\Security\Database\*.xml
%windir%\SoftwareDistribution\Datastore\Logs\Edb*.jrs
%windir%\Security\Database\*.cmtx
C:\pagefile.sys
C:\swapfile.sys
C:\hiberfil.sys
%allusersprofile%\NTUser.pol
%Systemroot%\system32\GroupPolicy\registry.pol
I collected some logs from a machine that took almost 4 hours to complete the update (from october 3rd, 10:40 to 14:05). I couldn't find any explanation for what I found. Some entries I repeatedly see on these logs are:
03/10/2024 11:17:29 debug update update process sending request: 07002000FVDB01300000920772499999 ##this numer seems random.
03/10/2024 11:59:58 debug av <appdbClient.msg 6> [file: , pid: 0]
03/10/2024 12:00:34 debug firewall scheduler called us
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hi,
Just to confirm, if the host machine has already got window 11 and you are trying to run normal updates or you are experiencing slowness while updating from win 10 to 11? If you are using full tunnel, how is the access speed for rest of the things?
Thanks,
Hello,
Thank you for trying to help.
All the machines have windows 11 already. So, it is an update from windows 11 (any version) to windows 11 24h2.
If by 'full tunnel' you mean ssl vpn through forticlient: then the access speed is fine. So far, no issues reported on vpn speed.
But anyway, just to make myself clearer, the slowness on this update happened on machines off-fabric (using vpn) and on machines on-fabric (connected directly to the company's network without the need for vpn).
Tks.
Hi,
Thanks for your reply. Since you have mentioned that the no access speed issue is noticed when connecting to another resource via FortiClient, may I suggest the below:
-To isolate the issue, do you mind trying to download a decent-sized file from https://www.thinkbroadband.com/download and note the speed? FYI, this link has nothing to do with the FTNT recommendation. I just googled to find resources available on the Internet.
-Review the link https://community.fortinet.com/t5/FortiGate/Technical-Tip-Using-DTLS-to-improve-SSL-VPN-performance/...and try to disable and enable DTLS tunnel to see any difference in behavior.
Thanks,
Atul
Will try the download part of your suggestion on the morning (it’s 11pm where I am now).
about the second recommendation, I honestly don’t see how dtls configuration can impact on this issue, as I have mentioned that the windows update takes too long for both off and on fabric users (with and without a vpn connection). Or am I not getting where you’re going with your troubleshooting logic?
tks.
Hi
Apologies as I have misread one of your previous messages and understood it in a sense where the host machines are working fine in updating the window when connected on-fabric.
Also, previously when you said "We tested machines without Forticlient and they finished updating in about 10 minutes", I assumed the update was working fine for any scenario as long as you not using client vpn.
Now its clear to me that the issue persist only when you are using FCT or when you are sitting inside your corporate LAN. But if you use your normal internet connection, things work as expected.
Just to clarify, you tested the connection works fine on the same end device?
I would also encourage you to raise a technical case using your EMS serial number.
Thanks,
Hi Atul,
Let me clarify that, once and for all.. haha:
There is no difference on windows update when comparing on/off fabric, nor when comparing vpn/no vpn. All of these scenarios present the said issue (windows 11 machines taking way too long to update to the 24h2 version).
Additionaly, the only problem we see is in this windows update. No other connection issue or speed problems.
So, I think it's something related to the forticlient analyses during windows update, such as antimalware, fortisandbox or something like that. Not anything related to vpn as the different connection scenarios don't change anything on the speed of the update.
The only scenario where the update happened quickly (10 minutes) was on a machine without the forticlient installed (it had it's forticlient and all it's protections uninstalled from the machine). In this case, the machine had only windows defender as it's endpoint protection and we couldn't test the same machine with the forticlient installed as the problematic update had already been installed.
Hope the situation is clarified now. But if you have any further questions, don't hesitate to ask. Thanks for the help.
Hi RGS,
Gday. I would advise review the doc https://community.fortinet.com/t5/FortiGate/Troubleshooting-Tip-FortiClient-user-cannot-access-inter...and for testing purpose, try remove KB2693643 and see if that makes a difference. This is a hit and trial approach for now since to investigate properly, its best to do it via a ticket with the TAC.
Thanks,
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1733 | |
1106 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.