Skip to main content
KavinduM99
New Member
February 23, 2026
Question

Need Bandwidth Utilization Report Between Two FortiGate Devices (Specific Interface & Time Range)

  • February 23, 2026
  • 2 replies
  • 297 views

Hi Fortinet Community,

We manage FortiGate firewalls for one of our customers with a multi-site setup consisting of one Main Plant and four Branch Plants. In the Main Plant and two of the Branch Plants, there is an additional isolated/internal FortiGate used only for internal communications.

Requirement

We need to generate a historical bandwidth utilization report for traffic from one specific Branch Plant to the Main Plant, passing through a VRF interface, for the below specific date/time windows.

Required Time Ranges

  • 27 January 2026: 9:15 AM – 9:45 AM
  • 28 January 2026: 9:20 AM – 9:40 AM

Traffic Details

  • Traffic Path: Branch Plant → Main Plant
  • Connectivity: Site-to-site IPsec tunnel, running over a VRF interface (specific interface)
  • Reporting Scope: Bandwidth utilization for the specific VRF/interface and IPsec tunnel traffic between these two sites
  • Tools Available: FortiGate + FortiAnalyzer (logs are available in FortiAnalyzer)

Output Expected

  • We are looking for a report that includes:
  • Inbound and outbound bandwidth (Mbps)
  • Traffic volume (Bytes)
  • Session count (if available)
  • Peak usage during the specified windows
  • Preferably in graph format and exportable (PDF/CSV)

Assistance Requested

  • Could someone please provide a step-by-step method to generate this report?
  • Specifically, guidance on the following would be appreciated:
  • What is the best method to generate historical bandwidth utilization for a specific VRF/interface within a defined time range?
  • How can we filter the report to show only traffic between the Branch FortiGate and the Main FortiGate (over the IPsec tunnel)?
  • Which approach is recommended in FortiAnalyzer:
    • Built-in reports (Interface bandwidth / VPN / Traffic)
    • Custom dataset + custom report
    • FortiView queries / Log View filters
  • If possible, could you share a sample dataset/query or recommended fields (e.g., srcintf/dstintf/tunnelid/service/bytes sent/received/session count) to build this report?

If anyone can share the recommended approach or a sample dataset/query, it would be very helpful.

 

Thank you in advance for your support.

2 replies

kvsivasakthi
New Member
February 23, 2026

Hi,
I don't think you can get the above historical details directly from the fortigate firewalls. It is possible if you are integrating your firewall interfaces / VRFs into external monitoring platform e.g Forti Analyzer or solarwind, etc..

But you can try the below approach,


Go to -> Log & Report → Monitor → Interface History

I am assuming you can get data for max 24 hrs directly from fortigate.

And you can schedule the report for fortigates, if you have forti analyzer in your env.


All the best !

KavinduM99
New Member
February 24, 2026

Hi,

 

Thank you for your response and for the clarification.

 

As you correctly mentioned, we are unable to retrieve the required historical details directly from the FortiGate firewall. The interface history on the device provides only limited data, and it does not cover the time range we are looking for.

 

However, FortiAnalyzer is already integrated and configured at the site. Therefore, we would like to proceed with obtaining the required historical interface/VRF-related data from the Analyzer.

 

Could you please guide us on the following:

  • How to generate historical interface utilization reports from FortiAnalyzer
  • The specific log type or dataset we should refer to
  • The recommended report template (if any)
  • Any necessary configuration steps to ensure the required data is being logged and retained

Your guidance on the correct procedure within FortiAnalyzer would be greatly appreciated.

 

Thank you in advance for your support.

farhanahmed
Staff
Staff
February 24, 2026

@KavinduM99  FAZ reports only run on the logs sent by the FGT and does not access FGT interface bandwidth (kbps/Mbps) directly.

 

You can refer to the billing report and see if that helps:
https://community.fortinet.com/t5/FortiAnalyzer/Technical-Tip-How-to-generate-Throughput-Utilization-Billing/ta-p/196655

Note that this requires you to wait for at least 24 hrs after enabling the settings to get the report populated.