Skip to main content
RoBau
New Member
September 3, 2018
Question

Internet Speed Problems with FG80D and 5.6.2

  • September 3, 2018
  • 2 replies
  • 8614 views

Hello,

 

we are a MSP with Fortigate Firewalls. One customer now has bis internet bandwith problems with his firewall FG80D and FW 5.6.2 in his office in Rumania. The problems started like 2-3 weeks ago, before everything worked just fine (VPN connection/ UTM Features). Their internet access should be almost 500MB/250MB but rigth now behind the FW they have not more than 20 MB DOWN and 40MB UP (which is really strange).

 

We were sure that this just can be a ISP problem since we didnt change anything on this firewall for months. Since we dont have people on site we checked with their IT support team. They met 2 times last week to check the line and these are the results:

> ONE PC behind the firewall in LAN and WAN connected to Fiber Router (normal status): not more than 20MB/ 40MB

> Same PC behind directly (with same IP configuration as fw) to the router: > 300 MB/ 250MB

> Same PC behind another Router with same configurtion WAN and LAN (as firewall): same results > 300MB/ 250MB

 

They are not more than 20-30 people in the office. FW memory is never higher than 60% and CPU is really low. Sessions are really normal and when everybody is working we dont see anything unusual. We tried to desactivate all UTM features in the policies and nothing. We opened a ticket with Fortinet but nothing sofar.

 

Having these results we really think that this can be a FG issue. We dont have any information if the ISP changed something in their network (MTU, etc.). We can exclude problems with switches, routers, PC problems, etc.

 

Any idea what we can do, we really didnt have this kind of problems with all other firewalls and since we dont have technicians there it is getting really complicated.

 

Thanks a lot for any help!

 

 

    2 replies

    omega
    New Member
    September 3, 2018

    Strange. We are chasing a similar Problem for days no and got no feedback from Fortinet so far.

    We are quite sure that everything has been fine a few weeks ago and there is no difference in our config.

     

    In our case the issue only occurs when there is concurrent traffic on different interfaces. E.g. User connects to a proxy in dmz and that proxy fetches from internet on wan1.

    Throughput drops to 6MB/s on a 60D and to 10MB/s on a 60E.

     

    You seem to have tested direct internet access over the fortigate?

    No changes in config (for logging etc.)?

    Ashik_Sheik
    New Member
    September 3, 2018

    Was this issue immediately after placing FGT in between or was working fine for a while and started this issue ?.Give us more details .

     

    I believe there may b configuration issue .Check if any traffic shaping is applied .After 5.4 may b traffic shaping rules are not under IPV4 .

     

    If the firmware is old kindly upgrade and check.

     

    Regds,,

     

    Ashik

    RoBau
    RoBauAuthor
    New Member
    September 3, 2018

    Hi,

     

    FG80D was working fine for more than 1 year, everything the same, ISP, connection, etc. Last time we changed something was upgrading to 5.6.2 (Firmware should be OK) in June 2018, since than no changes at all. One policy, but it should not affect at all.

     

    Again, behind the router with same PC they get over 300MB download. Once behind the FG right now we just get max. 18-20MB download.

     

    Traffic shaping should not be configured, I didnt configure the FW myselfe but there is no need for it and I dont see it in the configuration.

     

    Thanks!

    Ashik_Sheik
    New Member
    September 3, 2018

    Strange but without traffic shaping policy , it is nearly impossible FGT to limit bandwidth .

     

    You can try to create new policy and move the policy on the top without any filters or security profiles with source NAT and filter one source address and check the speed on the filtered machine .

     

    Regds,

     

    Ashik