Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
karthik
New Contributor

Network Slow - FG100D

Hi,

 

We are using fortigate firewall 100D, currently we are facing network slowness complain by our users. we dont know where can we check and what is the issue. all our policy has been set as any and all.

 

when i check the ISP speed is fine. this using internal swtich panel. public ip then private for internal users.

 

can any one guide me how to check and change the speed,?

13 REPLIES 13
karthik
New Contributor

Windows DNS

karthik

FG DNS

ttreat
New Contributor

I have been having some issues too and found this article that has a good summary of CLI commands you can run: 

 

https://blog.webernetz.net/2015/12/21/cli-commands-for-troubleshooting-fortigate-firewalls/ 

 

Specifically, I think a few good ones to start with would be: 

 

- get system status - get system performance status - diagnose sys top - diagnose sys to-summary

 

See if any CPU or RAM are pegged at high % usage and see which processes are using the most. 

 

I've had an issue lately where if I spend a lot of time in the GUI clicking in and out of different pages to look at and compare configurations it eventually bogs the firewall down to the point I can't access any devices plugged into the firewall switch ports and the Web GUI becomes slow or unresponsive. In the past I noticed many httpds processes had been spawned by jumping around in the GUI and killing a few of them would clear things up, but I'm not sure that is what is happening. I rebooted the last two times to restore functionality. I'm very good about updating to latest firmware. I'm at latest 6.0 now, and this behavior has happened to me at each of the last three versions I was on (5.3, 5.4, and now 6.0). 

 

I also had some slow web page loading issues when I first setup the firewall, but determined it was because I was using the DNS policy. In my experience, the DNS filter policy slowed things down unacceptably. When I put in my ISP's DNS servers pages loaded much faster. 

 

Just some thoughts. Hope this helps. 

TT

stuart_king

I have recently upgraded to 5.6.7 (From 5.4.8) and we have experienced two firewall "slow down" instances in 2 days.

I found the following symptoms;

1) They slow up for internet trafic.

2) Firewalls cannot be managed via wan interface.

3) Local users complain about slow performance / almost unusable.

4) You can manage them over internal interface via tunnels perfectly fine.

 

Rather than reboot the firewalls it felt/feels like it's a DNS issue with fortiguard.

 

Solution:

1) I found that going to system>Fortiguard> Fortiguard Filtering port (where ports were set to 8888) I set to  53 then applied but it didn't make any difference at all......

2) BUT then Put the it back to port 8888 and applied and it all jumps back into life perfectly, immediately !!!!!!!!!!!!

This is all I did. NOTHING ELSE.

 

This also occurred on another firewall of ours yesterday at York…. same problem…. same solution.

 

If this solves anyone elses issues I'd be happy to hear but in the menatime I have a call in with fortinet and will update this area with result.

 

To me it looks like a communications issue with fortigurard and 5.6.7.OS.... as all the resources of the firewall were as usual for us un-taxed.

Labels
Top Kudoed Authors