Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Greg_Hennessy
New Contributor

5.2GA FWF 60C NPLITE Offload mostly not working

FWF 60C 25 policies Running purely as a L3 packet filter with no UTM functionality enabled Upgraded from 5.07 to 5.2GA over the weekend. Seeing high sustained CPU load of > 60% , investigation via FortiView->All Sessions FortiASIC tab and diagnose sys session list | grep npu indicates that the only traffic offloaded to NPLITE is SIP on 5060 (I' m assuming that the SIP ALG is doing this automatically) Any others seeing this ? Regards Greg
4 REPLIES 4
rbn
New Contributor

Yes, I have a client where we have been investigating slow internet speeds for several weeks now. All the sudden i noticed that when I download a 1GB file, the CPU  skyrockets and goes to 99% and stays there for the whole download ... basically rest of the network is not working during that time. This is the second 60C we are testing (tried with my lab gate to se if it would work better)... so it almost looks like the 60C does not support 5.2 even though it is on the supported list.

 

Big problem and not ok if you ask me. Especially since the client has bought 4 FortiAP 221C so they need to be on 5.2 to support those... we did look all this up before getting them, so it is of course a disappointment to see this.

 

If any one has any input if this is a bug ore something that can be fixed... please do tell. Thanks

Dave_Hall
Honored Contributor

Just curious to know if you have any soft switches configured on the 60C -- if so the CPU on the Fortigate will have to copy/transfer the data between the port members of that soft switch.

 

Edit: How are the WAN connection(s) configured?  Have you tested for possible duplex/mismatch?  (There are a few posts already on troubleshooting speed issues, just use the search link at the top of the page.)

 

 

NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C

NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C
rbn
New Contributor

Yes, the FGT60C is in its standard switched setupt like it comes from the factory. Still, the FGT did not have these problems before... it still feels like it is FortiOS 5.2 that has messed up the machine.

emnoc
Esteemed Contributor III

Open a ticket with  FTNT support. This is why I 've always  taken the stance of not upgrading older hardware appliances to  5.2.x if you are not requiring any new features. I've kept all of my  "c" models on 4.0 MR3 train just because of this. These units are older lack less memory/cpu compared to a new appliance.

 

 

 

 

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
Labels
Top Kudoed Authors