900D to FGVM Throughput over 1GB P2P
I'm trying to find the root cause to a throughput problem between two Fortigate firewalls a HA pair of 900D's at the organizations main building and a remote data center.
With the help of several qualified engineers at the remote hosting site that hosts servers for 100's of customers two connections to the data center been provisioned. The primary is a 1GB AT&T P2P and for backup is IPsec VPN over a 500/500 Internet circuit.
Both circuits test as being fine; no interface configuration errors or latency problems and according to the ISP's the performance matches spec., but with that said neither circuit is usable to connect users in San Francisco to their data in a Irvine data center.
Both the 500/500 MB/s IPsec tunnel and the 1000 MB/s are unable to even come close to that promised performance having an asymmetrical throughput of about 112 MB/s IN and only 4.5 MB/s OUT.
I won't go into to all of the changes of SFP's, patch cables etc I've done trying to fix this but I will say the reason I'm convinced that the problem is local to the 900D and not somehow the remote data center is that I have a similar throughput problem between the 900D and the Office 365 cloud in that 20GB mailbox takes about 24-hours to transfer.
Is it possible that the Fortigate firewall is to blame?
Its primarily being used as a internal firewall separating two different user VLANs from four resource VLANs for PCI-DSS compliance so I have a ton of IP4 policies and use features like FSSO and I'm using many of the UTM firewall features were useful and the VLAN "routing" is happening on the 900D's.
Memory on the 900D's is around 60%
CPU on the 900D's is always less than 15%
I'm thinking that the firewall is overloaded is that possible and how do I test it to find out?
