Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Jeff_the_Network_Guy
New Contributor III

IPS killing downloads?

We have a 400A as our primary firewall that is currently running v4.0, build0632, 120705 (MR3 Patch 8). For months (and several FortiOS versions) we' ve have had problems with downloads and web browsing. It was very difficult to track due to a lack of consistency (" The Internet is slow....Waaahhhh!" ). Finally we figured out that exempting sites from IPS resulted in a marked improvement in reliability. It seems that if we have IPS turned on for the policy that governs our users' web browsing, we see a flurry of " deny status" with a message of " no session matched" . Downloads fail to complete, or report that they are complete but files are corrupt of only partially downloaded. We have tried to open a ticket with Fortinet on the issue but could never successfully navigate past level 1 support. If anyone has had a similar challenge I would love to hear how you resolved it.
----------------(-- Jeff
----------------(-- Jeff
25 REPLIES 25
Jeff_the_Network_Guy

We' ve been running this update network wide since 9/14 with no change in behavior.
----------------(-- Jeff
----------------(-- Jeff
cmberry

We' ve been running this update network wide since 9/14 with no change in behavior.
I read that it is possible that this bug only causes issues for people with 4+ CPU cores. (I have 6 cores). Might explain why not everyone has noticed it. Also, there must be some merit to the problem, as MS has announced they are looking into it.
Jeff_the_Network_Guy

I am not denying that his update could be the root cause for some people. In my situation, the problem has been ongoing for well over 6 months, which means it predates the patch. I tried working with Fortigate on the problem, but their support gets too focused on fixing the problem as demonstrated with one website, and tends to lose site of the scope of the behavior. It has not been too much of an issue since a large majority of the staff do not download files. It has become more of a challenge for me lately.
----------------(-- Jeff
----------------(-- Jeff
Jeff_the_Network_Guy

Does anyone know the circumstances behind bug 176978 " Traffic is randomly dropped by the Fortigate" that was fixed in MR3 patch 9? Could it be related to any of this?
----------------(-- Jeff
----------------(-- Jeff
cmberry

what' s the verdict? any luck?
Yes, 100% of my download and streaming problems went away as soon as I removed that MS update. No other changes to my fortigate were necessary. Honestly, I can' t believe this update problem is not getting more play. You would think it would be affecting alot more people.
messalina
New Contributor

Hi guys, me too thinks that it is actually more important to inspect the " outbound" traffic. most of the malware is coded to attack by http return packet stream, like the latest ms and java attacks that would give attacker an administrator level remote connection to infected workstations.
Labels
Top Kudoed Authors