Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
How is the 200E connected to the new line - through the RJ45 WAN ports or the SFP ports? By 500 gig symetrical line, I assume you mean a 500 Mbps symmetrical connection.
I would suspect possible duplex/speed mismatch between the 200E and the device on the other side of that 500 gig connection - on the 200E perform the following commands on the CLI:
diag hardware deviceinfo nic <interface name>
where interface name is the 500 gig connection - look for the duplex/speed lines and any rx/tx counter errors - if there are any counter errors, perform the same commands in say 5-10 mins and see those counter errors increase.
If you are no sure of the interface name, enter "diag hardware deviceinfo nic" without the interface name to get a list of interface names.
The fgt can only connect to the other side based on set rated speeds (eg. autonegotiation). you can check the possible detected duplex/speed options of an interface by typing the following on the CLI:
config system interface edit <interface name> set speed ?
The output would be similar to the following:
auto Automatically adjust speed. 10full 10M full-duplex. 10half 10M half-duplex. 100full 100M full-duplex. 100half 100M half-duplex. 1000full 1000M full-duplex.
I would also check or confirm the equipment on the other side of that 500 gig connection is set up properly.
NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C
The duplex/speed of the devices at both sides of that WAN connection should be left at auto negotiation. No actual need to adjust the duplex/speed on the fgt side unless you see any rx/tx error counters increasing on the port (via diag hardware deviceinfo nic <interface name>).
For a 500 Mbps symmetrical line connection, the WAN port connection to the WAN device should be at least showing 1000M full-duplex (if I am not mistaken).
Traffic shaping is generally not used/applied to the WAN connection - you may be thinking of rate-limiting. (Traffic shaping is mainly applied via firewall policy rules).
On the GUI, check the WAN <interface> connection and see if the Estimated Bandwidth values are set - if not, you should set them according to the expected bandwidth.
Keep in mind that applying various UTM features (via firewall polices) will slow down your device connection (behind the firewall) based on the traffic and amount of packet inspection involved.
When it comes down to it, you need to first confirm/determine if there is a connection/speed or other factors involve and the best way to do that is direct connect your laptop directly to the ISP equipment and run speeds tests that way.
NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1688 | |
1087 | |
752 | |
446 | |
227 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.