Question
Significant network performance drop
Hi Community,
Look like I am experiencing a significant throughput performance issue when I compare a iperf from Fortigate to a linux host. For examples, see some iperf snippet I below
FGT IPERF UPLOAD
- - - - - - - - - - - - - - - - - - - - - - - - -
[ ID] Interval Transfer Bandwidth Retr
[ 9] 0.00-20.00 sec 1.57 GBytes 675 Mbits/sec 0 sender
[ 9] 0.00-20.00 sec 1.57 GBytes 675 Mbits/sec receiver
LINUX IPERF UPLOAD
- - - - - - - - - - - - - - - - - - - - - - - - -
[ ID] Interval Transfer Bandwidth Retr
[ 4] 0.00-20.00 sec 819 MBytes 343 Mbits/sec 490 sender
[ 4] 0.00-20.00 sec 816 MBytes 342 Mbits/sec receiver
FGT IPERF DOWNLOAD
- - - - - - - - - - - - - - - - - - - - - - - - -
[ ID] Interval Transfer Bandwidth Retr
[ 9] 0.00-20.00 sec 2.13 GBytes 916 Mbits/sec 400 sender
[ 9] 0.00-20.00 sec 2.13 GBytes 916 Mbits/sec receiver
LINUX IPERF DOWNLOAD
- - - - - - - - - - - - - - - - - - - - - - - - -
[ ID] Interval Transfer Bandwidth Retr
[ 4] 0.00-20.00 sec 59.5 MBytes 25.0 Mbits/sec 282 sender
[ 4] 0.00-20.00 sec 58.9 MBytes 24.7 Mbits/sec receiver
The policy use for the taffic from linux host is the following, I have already disable all UTM feature
config firewall policy
edit 993
set srcintf "USERS"
set dstintf "ISP"
set srcaddr "users.4dc.host.netdisco"
set dstaddr "all"
set action accept
set schedule "always"
set service "ALL"
set logtraffic all
set ippool enable
set poolname "natpool-servers-general"
set nat enable
next
end
I can't figure out why that significant throughput drop. Any help would be appreciated
Thanx!
