Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Not applicable

ftp download

I download files from ftp site, if enable virus scan under protection file, can' t download file, what' s problem?
31 REPLIES 31
abelio
SuperUser
SuperUser

error messages? Maybe buffering process for AV analysis is taking too much time; Try comfort client settings and reduce buffering size.

regards




/ Abel

regards / Abel
Not applicable

What' s comfort client settings and reduce buffering size?
abelio

What' s comfort client settings and reduce buffering size?
You can configure that within ProtectionProfile->AntiVirus settings Details and full info in http://docs.forticare.com/fgt/techdocs/FortiGate_Administration_Guide_01-30007-0203-20080930.pdf and http://kc.forticare.com/default.asp?id=2066

regards




/ Abel

regards / Abel
Not applicable

I set Anti-virus' s ftp comfort_interval=20, comfort_amount=512, but can' t download, on my ftp client, " 502 Command REST not allowed by policy' comes out.
lmuir
New Contributor

With your settings you have enabled 512 bytes to be passed to the client every 20 seconds until AV has finished. I suggest you change this to something a little more usable. REST is to resume, well, to start at a specified part of the file. You cannot resume/thread a file if AV scanning is used on FTP, most clients will just start again from the beginning. Cheers, Lachlan.
Not applicable

Thanks all. I don' t unerstand Lachlan, what' s meaning for changing this to something a little more usable?
lmuir
New Contributor

Depending on your FGT model and load, you can take it up to interval 1 amount 10240 both values are maximum allowed. This means the FGT will send 10240 bytes of the file to the client every 1 second, until the file has been scanned. Setting it to its max can cause extra load on the FGT, so if your strapped for resources as it is, knock it down a notch. First try lowering the amount before the interval, most clients don' t care how little is coming through, as long as its regular. Cheers, Lachlan.
Not applicable

I set comfort client on antivirus , but can' t download anything. Antivirus scanning for ftp is not function on my fgt-60?
lmuir
New Contributor

Only guessing here but that might be true, i think those units have a small amount of RAM which may significantly limit the amount of AV scanning. What firmware are you running? Also, can you post the policy and profile config in question? Cheers.
Labels
Top Kudoed Authors