Astaro User Bulletin Board
Go Back   Astaro User Bulletin Board > Astaro Gateway Products > Web Security: HTTP/HTTPS/FTP, IM/P2P, Web Filtering and Antivirus

Welcome to the Astaro User Bulletin Board.
If this is your first visit, be sure to check out the FAQ by clicking the link above. You may have to register before you can post: click the register link above to proceed. To start viewing messages, select the forum that you want to visit from the selection below.

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 03-24-2009, 05:16 PM
Junior Member
 
Join Date: Mar 2009
Posts: 7
Default ftp proxy limiting download speed

Even if i have the antivirus scanning turned off the speed with which i can use ftp is limited to around 320 KB/s per connection. For example, if I'm just downloading one file it max's out at 320 KBs/s. If I download two files simultaneously I can get the same speed for both (~320 KB/s). If i turn the ftp proxy off and add a packet filter rule i can download at my connection's full speed. What's the FTP proxy doing that limits downloading speed?

Last edited by wrallen; 03-25-2009 at 05:17 AM. Reason: grammar
Reply With Quote
  #2 (permalink)  
Old 03-24-2009, 05:44 PM
BAlfson's Avatar
Moderator
 
Join Date: Mar 2007
Location: Oklahoma City
Posts: 4,954
Default

What are your throughputs if you do single-scan anti-virus? If you turn off AV?

If turning off AV fixes the speed issue, then you can put in an exception to forego AV scanning for the host or add it to the Transparent mode skiplist.
__________________
ACE V7 - Astaro Preferred Partner since V3
Addicted to my iPhone!
Reply With Quote
  #3 (permalink)  
Old 03-24-2009, 06:04 PM
Junior Member
 
Join Date: Mar 2009
Posts: 7
Default

Those are the speeds with AV turned off. I was wondering what it's doing that limits the speed per connection even with AV turned off.
Reply With Quote
  #4 (permalink)  
Old 03-24-2009, 06:23 PM
BAlfson's Avatar
Moderator
 
Join Date: Mar 2007
Location: Oklahoma City
Posts: 4,954
Default

I'd be interested to know if there's any slowdown when you are doing single- or double-scan with A-V.

What happens if you put the server into the transparent mode skiplist? Do you achieve the same result ans turning off the FTP proxy?
__________________
ACE V7 - Astaro Preferred Partner since V3
Addicted to my iPhone!
Reply With Quote
  #5 (permalink)  
Old 03-24-2009, 06:32 PM
Junior Member
 
Join Date: Mar 2009
Posts: 7
Default

Quote:
What happens if you put the server into the transparent mode skiplist? Do you achieve the same result ans turning off the FTP proxy?
same results
Reply With Quote
  #6 (permalink)  
Old 03-24-2009, 06:48 PM
BAlfson's Avatar
Moderator
 
Join Date: Mar 2007
Location: Oklahoma City
Posts: 4,954
Default

Well, that's a relief, but now I'm left with the same question you started with: What can it possibly be spending its time on if AV is turned off?

If you have support, this would seem like an anomaly that Astaro would be interested in knowing about.
__________________
ACE V7 - Astaro Preferred Partner since V3
Addicted to my iPhone!
Reply With Quote
  #7 (permalink)  
Old 03-24-2009, 07:45 PM
Moderator
 
Join Date: Jul 2001
Location: southern California
Posts: 4,928
Default

Try turning off the IPS, or adding an exclusion, to test if that is limiting the speeds.

What CPU are you using?

Barry
__________________
http://DealBert.net
Home & business end-user since v1.x
  • ASL 6.3x, HP DL145 Dual Opteron, 1GB RAM, 6 gigE NICs, 50-IP Platinum License
  • ASL 7.3x, Dell PE1550 Dual PIII 1GHz, 1GB RAM, 2 NICs, 50-IP Platinum License
  • ASL 7.501, 17-watt fanless mini-ITX system: MSI IM-945GSE-A Atom n270, 2GB RAM, Morex T3310 case. 2 Intel GigE, 3 VLANs. 80G 5200rpm 2.5" HD
    Netgear GS108T gigE VLAN switch & Linksys WRT54G WAP
    Total network infrastructure: 27 watts. 100-IP Home User. FiOS 10mb/2mb
Reply With Quote
  #8 (permalink)  
Old 03-24-2009, 09:02 PM
BAlfson's Avatar
Moderator
 
Join Date: Mar 2007
Location: Oklahoma City
Posts: 4,954
Default

I was thinking about that, too, Barry, but wouldn't the traffic get processed by IPS even if the FTP proxy was disabled?
__________________
ACE V7 - Astaro Preferred Partner since V3
Addicted to my iPhone!
Reply With Quote
  #9 (permalink)  
Old 03-24-2009, 09:10 PM
Moderator
 
Join Date: Jul 2001
Location: southern California
Posts: 4,928
Default

Sure, but as I said, you can add an IPS exclusion if necessary.

I doubt it's the IPS though, unless the CPU is very slow.

Barry
__________________
http://DealBert.net
Home & business end-user since v1.x
  • ASL 6.3x, HP DL145 Dual Opteron, 1GB RAM, 6 gigE NICs, 50-IP Platinum License
  • ASL 7.3x, Dell PE1550 Dual PIII 1GHz, 1GB RAM, 2 NICs, 50-IP Platinum License
  • ASL 7.501, 17-watt fanless mini-ITX system: MSI IM-945GSE-A Atom n270, 2GB RAM, Morex T3310 case. 2 Intel GigE, 3 VLANs. 80G 5200rpm 2.5" HD
    Netgear GS108T gigE VLAN switch & Linksys WRT54G WAP
    Total network infrastructure: 27 watts. 100-IP Home User. FiOS 10mb/2mb
Reply With Quote
  #10 (permalink)  
Old 03-24-2009, 09:34 PM
Junior Member
 
Join Date: Mar 2009
Posts: 7
Default

Quote:
Originally Posted by BarryG View Post
Try turning off the IPS, or adding an exclusion, to test if that is limiting the speeds.

What CPU are you using?

Barry
turning off IPS doesn't work, 3.2 GHz P4, 2 gigs of memory.

the only thing that seems to work is turning off the ftp proxy or adding the host to the ftp proxy skiplist.

the http/s proxy only takes off around 100 KB/s. the ftp proxy knocks off about 400 KB/s.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT. The time now is 03:21 PM.

 

Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.


These pages are specifically maintained for the discussion of firewall issues within the Open Source community, and might already reflect new alpha/beta releases under development. Please refer to our product specifications for the functionality of the actual release. Discussions of new/enhanced functionality does not constitute a commitment of Astaro, to integrate this functionality into future releases. issues within the Open Source community, and might already reflect new alpha/beta releases under development. Please refer to our product specifications for the functionality of the actual release. Discussions of new/enhanced functionality does not constitute a commitment of Astaro, to integrate this functionality into future releases.