Created on 09-28-2006 12:00 AM
Description | Troubleshooting steps when experiencing performance problems with HTTP traffic with FortiGuard Web Filtering enabled. |
Components |
|
Introduction | FortiGuard Web Filtering is enabled, and HTTP traffic is really slow. FortiGate Antispam performance can also be affected. |
Troubleshooting |
Enter this command from the CLI: diagnose debug rating If this returns a small number of servers (usually two), then it is likely that your ISP or an upstream security device is blocking UDP packets with low ephemeral destination ports (typically 1024-1035) to avoid a potential exploit against Microsoft Windows systems. Some of these ports are required to receive FDN server lists updates. Solution #1Have your ISP and/or upstream security device unblock UDP ports 1025 to 1035. Also ensure they are not blocking other TCP or UDP ports used by FortiGuard Web Filtering or Antispam.
For a complete listing of ports, see the related article "Traffic Types and TCP/UDP Ports".
Solution #2If your ISP blocks the lower range of UDP ports (around 1024), you can configure your FortiGate unit to use higher-numbered ports, using the CLI command: config system global where the
For example, you could configure your FortiGate unit to not use ports lower than 2048 or ports higher than the following range:
config system global
config system global |
Why does this happen? |
FortiGate units contact the FDN to get the latest list of FDN servers by sending UDP packets with typical source ports of 1027 or 1031, and destination ports of 53 or 8888. The FDN reply packets have a destination port of 1027 or 1031. If your ISP blocks UDP packets in this port range, the FortiGate unit cannot receive the FDN reply packets. As a result, the FortiGate unit will not receive the complete FDN server list. Using the second solution described in this article, you can select a different source port range for the FortiGate unit to use. Trial and error may be required to select the best source port range. You can also contact your ISP to determine the best range to use.
See also the related article "Troubleshooting FortiGuard". |
Related Articles
Technical Note: Traffic Types and TCP/UDP Ports used by Fortinet Products
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.