FortiGate VM + vCloud Director / Poor Performance
Has anyone here deployed a FortiGate VM in a vCloud Director environment? I am getting extremely poor performance with the FortiGate VM in my VCD environment. Here is how I have it setup:
FortiGate VM 64-bit, VMware version (hardware profile 7, vmxnet3)
Firmware 5.2.1
2 x CPU, 4GB of RAM (VM02 demo license)
port1 = VCD Direct Network (goes to a public /28 attached directly to our Cisco ASRs)
port2 = VCD isolated network used for the LAN
port3 = VCD isolated network used for the DMZ
The FortiGate VM is configured to act as the firewall and router for all 3 networks. North-South traffic seems to flow ok (LAN <-> WAN, and DMZ <-> WAN), but east-west traffic (LAN <-> DMZ) performs extremely poor. Something simple as copying a file between a host on the LAN and the DMZ takes forever (transfer rate <1Mbps). The configuration is as simple as it gets: All UTM functionality is turned off, two NAT policies to allow the LAN and DMZ to get out to the internet, and two rules to allow all traffic between the LAN & DMZ.
I can swap the FortiGate VM out for VyOS, pfSense, or vShield Edge...and with those 3 virtual appliances I can get file transfer speeds >250MB/sec. So I don't think it's a problem with the underlying infrastructure (Cisco UCS blades/chassis, Cisco Nexus 5596UP switches), otherwise I would expect similar results with the other appliances.
I'm working on a case with F-TAC right now, but I wanted to see if anyone out there had had a similar experience.
Anyone?
