Skip to main content
ASPCORP
New Member
May 5, 2015
Question

FortiGate 40C mbps

  • May 5, 2015
  • 3 replies
  • 6040 views

We're currently using a fortigate 40c and getting internet from a Tmark fiber connection.

 

If i connect a machine directly to the TMark switch my internet speed is 100mb + , but once i connect thru the fortigate its between 30 and 50.

 

Please help.

    3 replies

    mhe
    Explorer II
    May 5, 2015

    You've reached the Limit of your small box. Switch to flow based AV should help a Little; otherwise you have to disable UTM Features to get more traffic trough you 40c.

     

    martin

    ASPCORP
    ASPCORPAuthor
    New Member
    May 15, 2015

    We made these changes and still no luck

    Dave_Hall
    New Member
    May 16, 2015

    Hi Chris.

     

    It would help us a lot if you provided more information on how your 40C is setup, such as firmware, whether you have any soft switches setup, have tested for duplex/speed mismatch, CPU/memory usage, tailored UTM features to the traffic (e.g. separate firewall policies covering web traffic, DNS, email traffic, NTP, other, etc.)

     

    The specs for the 40C outline the throughput performance limits placed on the 40C with IPS/antivirus features enabled.   While it may be possible that your network has outgrown your 40C, limiting/tailoring the IPS/App control/antivirus policies to the traffic can go a long way.  (E.g. you don't want your fgt's IPS policy scanning for linux/MAC exploits if the traffic is windows-PC based traffic only.)

     

    emnoc
    New Member
    May 16, 2015

    B4 we thru the FGT40C out, have you double check and port interfaces errors?  I ran FG40C on 100mbps handoffs and didn't see or had any reports.

     

    I would run the diag hard commands and look for any interfaces errors 1st and then t-shot based on your findings.

     

    e.g

    ( gain your speed/duplex )

    diag hardware  deviceinfo nic wan1

     

    If duplex is not full this would be a direct impact to the BW you can push.