Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
xyratexTom
New Contributor

Slow FTP transfers behind FortiGate firewall

Hello, we currently run an estate of fortigate firewalls, some clustered, some standalone depending on site size. All devices are currently running v4.0 MR2 Patch 2 code and are managed with a FortiManager. We host a publicly accessible FTP server for product support at our HQ in Havant, UK. When users/engineers in other sites (Fremont, Sacramento Florida etc) try to download files from this site, their download speeds are appauling ~ 8KB/Sec. no FTP traffic is sent down VPN tunnels. We have tested downloading from our FTP site from outside out network and transfer speeds are normal, its just at our other sites that the speed is affected, where there is a fortigate present. On the policy the users will be using to access the FTP site, we have some UTM features enabled - Protocol options, IPS, Web Filtering and Application control. this policy is also locked down to the following protocols: FTP,FTP_GET,FTP_PUT,HTTP,HTTPS,NTP,PING and some custom services for MSN Messenger and HTTP Applications. this is where it gets strange: Tests performed today: default UTM is (Protocol options, IPS, WebFilter & App Control enabled with standard user-profiles) Application control is in a logging only mode. When running default UTM and allowing ' Any' service, small files seem to be slow, and large ones seem to be fast. When running default UTM and defined services like above, small files are fast and larger files are slow. When running no UTM and allowing ' Any' service, small files start fast then stall and larger files start fast, but then slow down dramatically. When running no UTM and defined services like above, small and large files start to run at a reasonable speed > 600KB/Sec , but do tend to slow down a lot or even stall. I have had a look in the release notes for various newer versions of firmware, including known issues in the current version and there doesn' t seem to be anything relating to this type of issue. This is reproducible in most our sites with a fortigate, but when downloading images from fortinets FTP site, the speed is maxed. If there are any tests you could recommend it would be much appreciated. Thanks
12 REPLIES 12
rwpatterson
Valued Contributor III

Is there any chance you could upgrade one of the devices and try it again?

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
xyratexTom

Yes, we do have a dev cluster which shows the same symptoms. What firmware would you recommend, MR2 at a later patch, MR3 etc? Many thanks for the quick response! Tom
rwpatterson
Valued Contributor III

From what I have been reading here, 4.2.4 seems to be the way to go. Avoid MR3 unless you have free time for chasing new bugs... :(

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
xyratexTom

brilliant, Ill test it and get back to you. Many thanks for the help!
Fullmoon
Contributor III

Hi, From fortinet docs info. This is a normal behavior. It doesn' t mean your FTP session is hanging. You need to wait for the file to be downloaded to the FortiGate. Here are the steps during an ftp download with antivirus enabled : 1) The file is first entirely downloaded to the FortiGate 2) The file is scanned for viruses on the FortiGate 3) The file is transferred to the PC (ftp client). So the PC only ' sees' the FTP packet coming on step 3. If the ftp server is slow, or the file is big, or your internet connection is slow, it may take some time for the FortiGate to achieve step 1). To prevent the PC FTP session from timing out, the FortiGate sends 1 byte from time to time to the PC.

Fortigate Newbie

Fortigate Newbie
bmann
New Contributor

There is " Comfort Client" future in the protocol options. Take a look on it. Do you use AV? How big files do you scan (in protocol options)? I think that if a file is bigger than limit (in protocol options) it should go fast (maybe there is slow start). I would try it with http download and test behaviour and then the same with ftp.
TopJimmy
New Contributor

I found sending 1200 bytes every 1 second (in Comforting) to work the best in our environment. This is using FGT620b' s and FGT800' s with various versions of FortiOS from 4.1.x through 4.2.4. I also had to change the session TTL for FTP so the session wouldn' t timeout before the FTP transfer completed due to a very low default timeout I have set for our environment. your mileage may vary.
-TJ
-TJ
xyratexTom

Hi All, many thanks for your responses! I don' t believe it is Antivirus, we currently don' t run any AV scanning as this caused issues last time we turned it on. I will look into the comfort clients though as this seems to be something that has never been configured on our FortiGates. I will get back to you once I have tried some things. Thanks guys
xyratexTom

Hi All, Right, Fortinet have also recommended configuring comfort clients but this has not made any difference. I have also adjusted the oversized file threshold to 1. I don' t know if it makes any difference, but we are running FSAE and Identity based policies on the rule FTP would be coming in on, could this have any effect? What is also strange is this does not affect clients like filezilla, only browser based FTP and windows explorer. I have made sure passive mode is enabled in IE and that makes no difference. The only other thing I can see on the local FortiGate (local to client) is that the device has been reaching its system connection limit in the alert console every few minutes, but I cannot figure out what is triggering this. Any help is appreciated!
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors