Skip to main content
enable1179
New Member
July 17, 2026
Question

Slowness over Forticlient to anything internal.

  • July 17, 2026
  • 3 replies
  • 82 views

We upgraded the firewalls from 7.4.2 to 7.6.6 and accessing anything internally over the forticlient connection is very slow.  Prior to the upgrade everything was good.

 

I have tried changing some of the tcp-mss-send/receive values but nothing seems to work.

 

Anyone have any suggestions on what to look at next other than upgrading to 7.6.7?

3 replies

YiheangLy
New Member
July 17, 2026

Try to disable IPv6 on your windows NIC

enable1179
New Member
July 21, 2026

Unfortunately this did not fix my issue.

Pr0xy
Visitor III
July 18, 2026

​@YiheangLy beat me to it… Sometimes depending on the upgrade and how you do it you could enable new features that may impact performance.  It typically isn’t the appliance, its something else… but remember you’re only as fast as your slowest connection/process.

One thing I'd check is whether the upgrade introduced a configuration or processing change rather than an appliance performance issue. A few areas I'd investigate:

  • Definitely check the IPv6 Settings and any configuration changes. Confirm IPv6 isn't introducing routing, DNS, or other added processing overhead, like policy-processing.
  • Check logging - add anything? extend anything?  did you add sync?  Are you hitting max and overwrites are taking longer? Logging and HA synchronization absolutely increases logging, cloud logging, or session synchronization which can add latency.
  • Check if you moved anything to Cloud services (processing, auditing, logging), this would absolutely slow things down if they were all internal.  
  • Check Carrier dependencies like HW acceleration/NPU offload status with some FortiOS upgrades can alter acceleration-related settings, causing VPN traffic to be processed in software instead of hardware.
  • Check the SSL inspection and security profiles applied to VPN traffic.  Anything added or changed?  if you’re not sure, you can temporarily test with SSL inspection, IPS, AV, and other UTM profiles removed to isolate overhead.  MTU/MSS and fragmentation. can be related.
  • Check QoS, SD-WAN, or traffic-shaping policies. Verify VPN traffic is still being prioritized as expected.

Given that performance was normal before the upgrade, I'd focus on identifying a feature, inspection profile, acceleration setting, or processing path that changed between 7.4.2 and 7.6.6 before assuming it's a hardware limitation or immediately upgrading again.  I always do a compare and check the forums for things like this before upgrading.  

So Sayeth the Pr0x1
Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.