Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Not applicable

ftp download

I download files from ftp site, if enable virus scan under protection file, can' t download file, what' s problem?
31 REPLIES 31
Not applicable

firmware is FortiOS 3.00 MR6 patch 3. firewall policy and profile is as follows, edit 35 set srcintf " internal" set dstintf " wan1" set srcaddr " Ftpuser_group" set dstaddr " Ftpadd_group" set action accept set schedule " all time" set service " ANY" set profile-status enable set logtraffic enable set profile " full_scan" set nat enable next edit " full_scan" set ftpcomfortinterval 20 set ftpcomfortamount 512 set log-ips enable set log-im enable set log-p2p enable set log-voip enable set log-spam enable set log-av-virus enable set log-av-block enable set log-av-oversize enable set log-web-content enable set log-web-filter-activex enable set log-web-filter-cookie enable set log-web-filter-applet enable set log-web-url enable set log-web-ftgd-err enable set ftp clientcomfort scan splice unset http unset https set imap spamfssubmit set pop3 spamemailbwl spamfsip spamfschksum spamfssubmit spamfsurl set smtp spamfsip spamfschksum spamfssubmit spamfsurl splice set pop3-spamtagtype subject set imap-spamtagtype subject set spamemaddrtable 1 set nntp no-content-summary set ips-sensor-status enable set ips-sensor " protect_client" unset im set comment " " set msn enable-inspect set p2p enable set ftgd-wf-disable all next
lmuir
New Contributor

Hrmmm, looks ok to me, except ftpcomfortinterval and ftpcomfortamount, which your FTP client mightn' t like. What logs are generated on the FGT when you attempt to download a file over FTP?
Not applicable

What logs refer to?
lmuir
New Contributor

If you dont have a FAZ, it might be harder. Event and AV logs might help. Do you syslog to anywhere?
Not applicable

Yes, I syslog to a linux system. How can I extract this from syslog server?
lmuir
New Contributor

Umm, where ever you' re logging to. Might be a file or database.
Not applicable

From my syslog server, the log as follows, Nov 10 09:21:18 bogon date=2008-11-10,time=09:20:53,devname=Fortigate-60,device_id=FGT-XXXXXXXXXXXX,log_id=0021010001,type=traffic,subtype=allowed,pri=notice,vd=root,SN=2596761,duration=130,user=N/A,group=N/A,rule=35,policyid=35,proto=6,service=1941/tcp,app_type=N/A,status=accept,src=192.168.8.100,srcname=192.168.8.100,dst=207.25.253.40,dstname=207.25.253.40,src_int=" internal" ,dst_int=" wan1" ,sent=208,rcvd=3142,sent_pkt=5,rcvd_pkt=5,src_port=1198,dst_port=1941,vpn=N/A,tran_ip=XXXXXXXXXX,tran_port=52798,dir_disp=org,tran_disp=snat, Nov 10 09:21:41 bogon date=2008-11-10,time=09:21:20,devname=Fortigate-60,device_id=FGT-XXXXXXXXXXXX,log_id=0021010001,type=traffic,subtype=allowed,pri=notice,vd=root,SN=2597142,duration=130,user=N/A,group=N/A,rule=35,policyid=35,proto=6,service=25908/tcp,app_type=N/A,status=accept,src=192.168.8.100,srcname=192.168.8.100,dst=207.25.253.40,dstname=207.25.253.40,src_int=" internal" ,dst_int=" wan1" ,sent=208,rcvd=992,sent_pkt=5,rcvd_pkt=4,src_port=1206,dst_port=25908,vpn=N/A,tran_ip=XXXXXXXXXXX,tran_port=52965,dir_disp=org,tran_disp=snat, Nov 10 09:21:42 bogon date=2008-11-10,time=09:21:24,devname=Fortigate-60,device_id=FGT-XXXXXXXXXXXX,log_id=0021010001,type=traffic,subtype=allowed,pri=notice,vd=root,SN=2597203,duration=130,user=N/A,group=N/A,rule=35,policyid=35,proto=6,service=3343/tcp,app_type=N/A,status=accept,src=192.168.8.100,srcname=192.168.8.100,dst=207.25.253.40,dstname=207.25.253.40,src_int=" internal" ,dst_int=" wan1" ,sent=168,rcvd=474,sent_pkt=4,rcvd_pkt=4,src_port=1207,dst_port=3343,vpn=N/A,tran_ip=XXXXXXXXXX,tran_port=52993,dir_disp=org,tran_disp=snat, Any problem?
rwpatterson
Valued Contributor III

Why are the three destination ports non standard? Are the services set up in the helper as FTP services?

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com

I don' t understand destination ports non standard. How check ftp service settup in the helper?
rwpatterson
Valued Contributor III

Nov 10 09:21:18 bogon date=2008-11-10, ... ,src_port=1198,dst_port=1941,vpn=N/A,tran_ip=XXXXXXXXXX,tran_port=52798,dir_disp=org,tran_disp=snat, Nov 10 09:21:41 bogon date=2008-11-10, ... ,src_port=1206,dst_port=25908,vpn=N/A,tran_ip=XXXXXXXXXXX,tran_port=52965,dir_disp=org,tran_disp=snat, Nov 10 09:21:42 bogon date=2008-11-10, ... ,src_port=1207,dst_port=3343,vpn=N/A,tran_ip=XXXXXXXXXX,tran_port=52993,dir_disp=org,tran_disp=snat,
That' s what I mean by ' non standard' port. FTP is TCP 21.

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
Labels
Top Kudoed Authors