Hello,
we currently run an estate of fortigate firewalls, some clustered, some standalone depending on site size.
All devices are currently running v4.0 MR2 Patch 2 code and are managed with a FortiManager.
We host a publicly accessible FTP server for product support at our HQ in Havant, UK.
When users/engineers in other sites (Fremont, Sacramento Florida etc) try to download files from this site, their download speeds are appauling ~ 8KB/Sec.
no FTP traffic is sent down VPN tunnels.
We have tested downloading from our FTP site from outside out network and transfer speeds are normal, its just at our other sites that the speed is affected, where there is a fortigate present.
On the policy the users will be using to access the FTP site, we have some UTM features enabled - Protocol options, IPS, Web Filtering and Application control.
this policy is also locked down to the following protocols: FTP,FTP_GET,FTP_PUT,HTTP,HTTPS,NTP,PING and some custom services for MSN Messenger and HTTP Applications.
this is where it gets strange:
Tests performed today:
default UTM is (Protocol options, IPS, WebFilter & App Control enabled with standard user-profiles) Application control is in a logging only mode.
When running default UTM and allowing ' Any' service, small files seem to be slow, and large ones seem to be fast.
When running default UTM and defined services like above, small files are fast and larger files are slow.
When running no UTM and allowing ' Any' service, small files start fast then stall and larger files start fast, but then slow down dramatically.
When running no UTM and defined services like above, small and large files start to run at a reasonable speed > 600KB/Sec , but do tend to slow down a lot or even stall.
I have had a look in the release notes for various newer versions of firmware, including known issues in the current version and there doesn' t seem to be anything relating to this type of issue.
This is reproducible in most our sites with a fortigate, but when downloading images from fortinets FTP site, the speed is maxed.
If there are any tests you could recommend it would be much appreciated.
Thanks