Ive noticed over the past few installs, 5.4 and 5.2.5, that after installing, and even after a reboot, my NIC shows it is getting data at 8MB/sec. I have to shutdown forticlient and sometimes reboot, then will go to normal.
I first noticed this in my lab environment after installing EMS and pushing out to 3 servers, it eventually brought down my entire network and killed CPU and NIC traffic, i had to power off two esx hosts and my SAN, switch and start fresh.
Since then, i have noticed this on clients, mostly they are Windows 10 installs, yet there are a few Windows 7 pc's i notice this on.
Anyone else having related issues or possibly know?
Thank you
Thanks Chris. I can probably do that. I will probably just hang tight for the 5.4.1 release at this point, March is right around the corner.
--Alan
Could you try Windows build 788?
https://www.dropbox.com/sh/cb0j4pxw1f8nq84/AABHzZW1bpx1VjzYAmiK00S9a?dl=0
It has some fix for Application FireWall.
Thanks.
I will test this build tonight and let you know.
Thank you
I just had the same sort of issue on our network with FortiClient 5.4. Whenever firewall is enabled through custom FortiClient XML, cisco router starts heavy IGMPv2 traffic. Ticket number is 1606251. Never noticed this with 5.2.3.
Alan
Alan,
It's good to try b788, too.
I have narrowed it down to the client triggering massive IGMPv2 messages from the router to the multicast address of 224.0.0.1. If I disable the FireWall section in my custom XML file the broadcast storm stops. Very odd. I have not tried b788 yet. Will do that today.
Alan
Very interesting, when installing 7.88 it installed fine and I noticed windows updates were available. The pc's then got a warning about detecting malware. It was remnants of CryptoWall we had in the spring. Once I cleaned out the users temp folder and the system temp folder the malware warning went away and the updates installed. I am seeing normal network activity now.
Alan
W32/Filecoder.EM!tr was the virus found with realtime protection. It found restore_files_geeuh.html in a c:\windows\assembly folder. Once I emptied the temp folders this went away.
Alan
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1739 | |
1108 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.