We have had some problems recently with aborted FTP transfers and also (unrelated, or so we thought) delayed/stalled HTTP downloads.
On the FTP transfers we found that sometimes we got an alert on the logs, stating "Content Awareness - Error: Internal system error (1000)"
The Fail Mode for Content Awareness is set to Allow all requests (fail-open) but apparently it interferes with traffic anyway.
The second issue, with stalled HTTP downloads, we at first suspected was due to Threat Emulation.
Files would download almost completely and then stall for 1 to 4 minutes.
However, there were no logs from TE blade indicating these files were uploaded and emulated, nor were there any files stuck in TE queue.
We made exceptions in the policy to disable all Threat Prevention blades for this traffic, but that did not help.
But I remembered something from about a year ago with CA doing strange stuff, so we tried disabling it completely, unchecking it on the gateways, not just removing protocols from CA settings.
And lo and behold, downloads started to complete without delay!
Has anyone experienced similar issues?
In the case of HTTP downloads, they would eventually complete and files were correct, but no signs of anything wrong in the logs.
We really want to be able to have CA active, to block clients downloading .EXEs etc, but currently we need to have it off.