Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
bartman10
Contributor

200D-SSLVPN= 60% CPU on FG, IPSEC=0-5%

Before I sent my 200D to my admin in India I wanted to try some client VPN preformance so I hooked it up to the internal network all on gigabit. Use FortiClient to connect to the 200D then access shares on my computer running on a SSD drive. Transfer speeds where about the same for both SSL-VPN and IPsec-VPN.. about 45-50MB/s.. but CPU usage on SSL-VPN was about 60% on both CPU cores and almost 0% when using IP sec. CPU would go up as soon as I started the SMB transfer and go down as soon as it stopped, only on SSLVPN. Exact same settings for both SSL and IPsec.. CPU did not really matter if I disabled/enabled any filtering/IPS/antivirus... The only dif was the SSL.. To me it " feels" like the 200D was not offloading the SSL encoding to the NPU or what ever it' s called.. but IPsec was able to offload the encryption... Anyone have any thoughts, input..

300E x3, 200D, 140D, 94D, 90D x2, 80D, 40C, handful of 60E's.. starting to loose track.

Over 100 WiFi AP's and growing.

FAZ-200D

FAC-VM 2 node cluster

Friends don't let friends FWF!

300E x3, 200D, 140D, 94D, 90D x2, 80D, 40C, handful of 60E's.. starting to loose track. Over 100 WiFi AP's and growing. FAZ-200D FAC-VM 2 node cluster Friends don't let friends FWF!
3 REPLIES 3
Jupiter_FTNT
Staff
Staff

Yes, NPU does handle some IPSec traffic. You can use " dia vpn ipsec status" to check. SSL traffic are done in CP , under sys global , sslvpn-cipher-hardware-acceleration sslvpn-kxp-hardware-acceleration sslvpn-max-worker-count You can use " dia vpn ssl hw-acceleration-status" to check the HW status.
bartman10
Contributor

Great.. thanks for the reply. I will check this once the unit is installed in India.. it' s on a container ship headed there now. BTW.. what a refreshing experience FortiNet warranty is! They said I could transfer the unites anywhere in the globe and the unit is still supported! I know other companies lock hardware into the region where it was purchased.. so you CANT transfer them to other locations.

300E x3, 200D, 140D, 94D, 90D x2, 80D, 40C, handful of 60E's.. starting to loose track.

Over 100 WiFi AP's and growing.

FAZ-200D

FAC-VM 2 node cluster

Friends don't let friends FWF!

300E x3, 200D, 140D, 94D, 90D x2, 80D, 40C, handful of 60E's.. starting to loose track. Over 100 WiFi AP's and growing. FAZ-200D FAC-VM 2 node cluster Friends don't let friends FWF!
bartman10
Contributor

Also.. I wanted to note.. This message about CPU does not seem to affect transfer speed or performance... it' s just an observation. The test case is also not likely to be seen during real world use... A 200D with 1 VPN user pulling over 50MB/s... not really gonna happen in the wild... but again.. if it did... the only thing I noticed is the CPU graph at 50%.. that' s it..

300E x3, 200D, 140D, 94D, 90D x2, 80D, 40C, handful of 60E's.. starting to loose track.

Over 100 WiFi AP's and growing.

FAZ-200D

FAC-VM 2 node cluster

Friends don't let friends FWF!

300E x3, 200D, 140D, 94D, 90D x2, 80D, 40C, handful of 60E's.. starting to loose track. Over 100 WiFi AP's and growing. FAZ-200D FAC-VM 2 node cluster Friends don't let friends FWF!
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors