Skip to main content
mchupin
New Member
September 4, 2025
Question

Fortigate 60F Shaping Profile Not working

  • September 4, 2025
  • 3 replies
  • 690 views

We're facing an issue where traffic shaping on our FortiGate 60F device doesn't seem to be working as expected.Despite setting up the necessary configurations, no traffic appears to be shaped — the system always shows strange current-bandwidth (diagnose netlink interface list) when monitoring shaping statistics. Same configurations works well on Fortigate 100E. At same time shared shaping and per-ip shapers works as expected on Fortigate 60F.

The only thing that makes shaping profiles work on Fortigate 60F is disabling ASIC Offloading in the relevant firewall policy. But we wouldn't want to do that because all the traffic would go through the CPU.

FortiOS version 7.2.9 - 7.2.11

The real upload bandwidth is about 8 Mbps, but the system shows as 27kbps

Снимок экрана 2025-09-04 в 12.54.19.pngСнимок экрана 2025-09-04 в 12.53.50.pngСнимок экрана 2025-09-04 в 12.53.30.pngСнимок экрана 2025-09-04 в 12.53.06.png

 

3 replies

BillH_FTNT
Staff
Staff
September 4, 2025

Hi @mchupin 

The FortiGate 100E and 60F models use different NPU drivers. I will investigate your case and try to reproduce it in my lab.

Could you please share some additional information to help with troubleshooting?
I’m Bill from Fortinet. If possible, please send the details to my email: bhoang@fortinet.com.

 

1- Configuration (it is very helpful if I try to reproduce the same configuration with you, if fact all things are same is perfect)

2- dia sys session list ( the session related to traffic you want to set QOS)

3- Output of NPU commands :

diagnose npu np6xlite dce 0
diag npu np6xlite anomaly-drop 0
diag npu np6xlite sse-stats 0
diag npu np6xlite session-stats 0

 

Regards

Bill

BillH_FTNT
Staff
Staff
September 11, 2025

Hi @mchupin 

 

From your pictures, it looks like the shaping policy is also activated along with the shaping profile. For outgoing traffic, the device may process the shaping policy first if the traffic is offloaded to the NPU. Therefore, please remove the shaping policy when performing the test. Many thanks!

 

Bill

BillH_FTNT
Staff
Staff
September 11, 2025

Hi @mchupin 

Please disregard my earlier comment. There's no need to test on your site; I have already successfully reproduced the issue in my lab. I will work with the Engineering team on this and will provide updates here once I receive more information from them. Thanks

 

Bill

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!