FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
Not applicable
Article Id 197225

Description
One common issue when using a FortiGate unit with antivirus configure, is slow traffic or traffic timeouts specifically with Apple iTunes downloads.

This article shows the steps to improve this so that no downloads from this site will fail. This procedure makes use of the Exempt features which allow traffic from a certain site to bypass all proxy actions.

Solution
iTunes connects to apple.com to download music. The FortiGate unit will buffer anything it downloads up to the antivirus threshold before it sends anything to the client software. iTunes has a problem with this and thinks the connection is down due to the delay.

You need to set up a URL exemption for apple.com to disable antivirus scanning from that website. Add apple.com to a Web Filter table, select Filter Exceptions and use an action of Exempt.

To allow a bypass for iTunes:

  1. Go to Web Filter > URL filter > Create New. (Note, in FortiOS 4.0, this is located in UTM > Web Filter > Web Content Exempt).
  2. Create a new group name and select OK.
  3. Select Create New and enter the following and select OK.
    • URL - apple.com
    • Type - simple
    • Action - exempt.
  4. Go to Firewall > Protection Profile.
  5. Select Edit for the required protection profile.
  6. Select the blue arrow for Web Filtering to expand the options.
  7. Select the check box for Web Content Exempt, and select the filter group created in the steps above.
  8. Select OK.

 

Contributors