Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Rick_Rushing
New Contributor

Need to increase file size threshold above 12MB....any ideas?

hello, I download many files bigger than the threshold max, anyway to get it to do that? thx Rick
9 REPLIES 9
Not applicable

I' m not sure why you want to increase it. If the FG won' t let you download something >12MB, then the first place you should check is your content policy. Perhaps you are blocking files.
Not applicable

On a rule you use a content profile (like strict, scan etc) go to the profile you are using and change it, or create a new one to use which allows passing of " oversized files" for HTTP (or FTP, IMAP, POP, SMTP) Probably you have BLOCK selected as an action for oversized files in your cintent profile. Oversized files are NOT checked for viruses after the first xxMB you have checked. That means if a virus is on the end of the file it will not be checked. Dont worry most viruses are small files (file viruses are scarce nowdays) Good luck
Not applicable

I agree, your best bet might be to either check your scanning and blocking policies and see what is happening there. It took us a while to hammer out what we could and couldn' t block before we found a nice balance of security and useability.
Not applicable

Little Snippet of the future for you all... Whilst File Size blocking will always be determined by the amount of RAM inside an particular FG device, 2.8 will allow you to scan larger file sizes by caching to disk first... In the case of anything below the FG200 your in a little trouble, but this is good news for FG200+ Customers... Regards Nobby
Not applicable

Hi! I don' t understand: i' ve configured my FG-60 to pass oversized files/emails but anything i tried as soon the file i wanted to download is larger than the oversize file threshold i got the message " Sorry the file " ..." has been blocked. The file is larger than the configured file size limit" . I' ve created a new content profile in which i allowed to pass oversized files ...??? perhaps someone has an idea or a solution? thanks Schitti
Not applicable

It could be a rule above your which uses a more strict profile. Verify that the rule that allows the pass is higher than others
Not applicable

oh, I' m an idiot - i just looked at the wrong rule/wrong direction (internal->wan1 not wan1->internal)! thank you!
Not applicable

I don' t even set the file size 2 MBytes. Most files larger than a couple hundred k will be downloaded and then ran, so local antivirus should get it. The biggest threat is viruses embedded in the web page. This is where the virus (or usually a trojan) would never hit the hard drive and it process directly off the web page. In this case, the Fortigate triumphs over all other firewalls because it blocks that stuff. All Fortinet needs to do is FIX THE BUGS.
Not applicable

They could use a Virtual Paging file, that would help with larger files, Eg 35 HD - 10% of paging file that would be 3.5 GB of space for temporary processing...
Labels
Top Kudoed Authors