Skip to main content
mazbii
New Member
September 6, 2024
Question

Moved to Forticlient. Very slow when PC is downloading anything

  • September 6, 2024
  • 3 replies
  • 1940 views

We've moved a bunch of PC's from Anyconnect to Fortclient which has gone well however the big thing we've noticed is that if a host is downloading/streaming something then the Forticlient is affected quite badly.

So for example we use Forticlient to connect to our office and then RDP to a desktop machine on a private IP 192.168.1.1 for example. If I do a constant ping to 192.168.1.1 then the responses are fine. If I download anything then the response times climb so high as to be unuseable. It's only traffic to the 192.168.1.0/24 network which goes across the SSL-VPN. Any other traffic uses the home internet circuit gateway.

Normally I'd be 'yea, this is fine, you are using all the bandwidth' but this doesn't happen with Anyconnect at all. It's like the Forticlient isn't splitting off some bandwidth to stay stable where as Anyconnect is?

Is there a way to make Forticlient more stable if the host is using banwidth. I feel silly asking it as instintively I would say no of course not, tell your users to stop downloading when connected but again. They don't have this issue on Anyconnect.

3 replies

miciti
Visitor III
September 6, 2024
SonaMuvv
Staff
Staff
September 6, 2024

Hello,

If the issue still persists, Kindly check the below settings as well from the Fortigate side.

https://community.fortinet.com/t5/FortiGate/Troubleshooting-Tip-SSL-VPN-slow-file-transfer-issue/ta-p/230161

Pr0xy
Visitor III
July 18, 2026

I just posted something similar in another thread and it may apply here: Sometimes depending on the upgrade (or change) and how you do it you could enable new features that may impact performance.  It typically isn’t the appliance, its something else… but remember you’re only as fast as your slowest connection/process.  One thing I'd check is whether if any change (esp. upgrades) introduced a configuration or processing change rather than an appliance performance issue. A few areas I'd investigate:

  • Definitely check the IPv6 Settings and any configuration changes. Confirm IPv6 isn't introducing routing, DNS, or other added processing overhead, like policy-processing.
  • Check logging - add anything? extend anything?  did you add sync?  Are you hitting max and overwrites are taking longer? Logging and HA synchronization absolutely increases logging, cloud logging, or session synchronization which can add latency.
  • Check if you moved anything to Cloud services (processing, auditing, logging), this would absolutely slow things down if they were all internal.  
  • Check Carrier dependencies like HW acceleration/NPU offload status with some FortiOS upgrades can alter acceleration-related settings, causing VPN traffic to be processed in software instead of hardware.
  • Check the SSL inspection and security profiles applied to VPN traffic.  Anything added or changed?  if you’re not sure, you can temporarily test with SSL inspection, IPS, AV, and other UTM profiles removed to isolate overhead.  MTU/MSS and fragmentation. can be related.
  • Check QoS, SD-WAN, or traffic-shaping policies. Verify VPN traffic is still being prioritized as expected.

Given that performance was normal before, I'd focus on identifying a feature, inspection profile, acceleration setting, or processing path that changed before assuming it's a hardware limitation or consider downgrading or upgrading.  I always do a compare and check the forums for things like this and hope someone had a similar experience and can share.  Thanks to all of you who do!

So Sayeth the Pr0x1
Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!