Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
xyratexTom
New Contributor

Slow FTP transfers behind FortiGate firewall

Hello, we currently run an estate of fortigate firewalls, some clustered, some standalone depending on site size. All devices are currently running v4.0 MR2 Patch 2 code and are managed with a FortiManager. We host a publicly accessible FTP server for product support at our HQ in Havant, UK. When users/engineers in other sites (Fremont, Sacramento Florida etc) try to download files from this site, their download speeds are appauling ~ 8KB/Sec. no FTP traffic is sent down VPN tunnels. We have tested downloading from our FTP site from outside out network and transfer speeds are normal, its just at our other sites that the speed is affected, where there is a fortigate present. On the policy the users will be using to access the FTP site, we have some UTM features enabled - Protocol options, IPS, Web Filtering and Application control. this policy is also locked down to the following protocols: FTP,FTP_GET,FTP_PUT,HTTP,HTTPS,NTP,PING and some custom services for MSN Messenger and HTTP Applications. this is where it gets strange: Tests performed today: default UTM is (Protocol options, IPS, WebFilter & App Control enabled with standard user-profiles) Application control is in a logging only mode. When running default UTM and allowing ' Any' service, small files seem to be slow, and large ones seem to be fast. When running default UTM and defined services like above, small files are fast and larger files are slow. When running no UTM and allowing ' Any' service, small files start fast then stall and larger files start fast, but then slow down dramatically. When running no UTM and defined services like above, small and large files start to run at a reasonable speed > 600KB/Sec , but do tend to slow down a lot or even stall. I have had a look in the release notes for various newer versions of firmware, including known issues in the current version and there doesn' t seem to be anything relating to this type of issue. This is reproducible in most our sites with a fortigate, but when downloading images from fortinets FTP site, the speed is maxed. If there are any tests you could recommend it would be much appreciated. Thanks
12 REPLIES 12
bmann
New Contributor

What box do you have? What services are running/using at this box?
xyratexTom

Hi, this one is a FortiGate 300A, only running WebFiltering, IPS and standard sort of features. I have tried disabling some features to reduce memory usage, and after a reboot it looks good until I try more FTP transfers in which case in enters conserver mode. We have been thinking that maybe AV is turned on somewhere and not showing in the web console?! Has anyone had anything strange happen when upgrading from 4.1.x to 4.2.4? we did have some issues with clustered devices and fortigates losing bits of config during the upgrade. I' m going to look in the CLI for any extra settings not in the web console which may give me a clue. Thanks
xyratexTom

Hi All, Just want to say thanks for your help and as per usual, the network was not at fault here! After getting someone to look at the ' virtualised' FTP server, we found issues! Many thanks for the help though! Tom
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors