Major lags with enabled web filter on FortiGate 70G (FortiOS 7.4.8 & 7.4.9)
I have a FortiGate 70G (tested with FortiOS 7.4.8 & 7.4.9) in use at a customer site. The FortiGate is connected to FortiClient EMS Cloud and FortiAnalyzer Cloud. When I enable the most basic web filter (in the policy’s security profiles: only Web Filter: “Default” and SSL Inspection: “certificate-inspection”), websites take an extremely long time to load for users — and eventually they just pop up all at once.
Following the packet flow, where you can see that it takes 23 seconds before the next data packets appear.

I can’t explain this behavior and don’t really know how to analyze it further in detail — maybe someone has an idea or suggestions for additional analysis. I’ve already checked the processes (wad), but couldn’t identify any anomalies there.
The accessed page was timebutler.de, but the issue also occurs on other sites. If I remove the web filter, everything runs completely normal. The logs don’t show that anything is being blocked when the web filter is enabled.
It would be great if you have any ideas or suggestions — thanks!
Best regards,
Karsten
