- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
50MB fiber. Can't get above 10MB down. Upload is fine Fortiwifi 60E firmware 7.2.10
Hi Everyone,
We've been struggling with this for a couple months now. I'm wondering if anyone has even had a similar issue like this. This location switched to ATT fiber a few months ago. Right from the start we've never been able to get more than 10MB down when running speed tests. They have a 50/50MB connection. The bandwidth monitor on the status page also confirms download never getting above 10MB. Upload gets up to the mid 40s during speed tests every time.
We connected a laptop directly to ATTs equipment, ran a speed test and get 45ish down as expected. Naturally we've been treating this as a firewall config issue up to this point. Here's a list of everything we've tried so far
- ATT asked to have us set our WAN port to 100full duplex which it is. We also tried auto negotiate and 100half duplex.
- disconnected all equipment from the firewall except for one computer. Created a bare bones policy for that computer and put in at the top of the internal to wan1 policy section.
- carved out a port from our hardware switch to be it's own interface. Created one wide open policy out to the internet.
- Replaced the unit with a Fortigate 60F.
- Replaced the unit with another FortiWifi 60E. Used a config file from one of our other 800ish locations, only changed the WAN IP/Static route settings so it could get to the internet at the problem location.
- Had Fortinet look over the firewall. Told them testing with a laptop plugged into ISP equipment works fine. After trying some things they are blaming ISP equipment.
- ATT won't do anything because removing the firewall from the chain "fixes" the issue.
Apologies for the wall of text. I apricate any suggestions. If any one wants any further information I'll happy to provide it.
- Labels:
-
FortiGate
-
WAN optimization
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi,
If fragmentation is induced, then most likely we achieve lower throughputs
Please check from the host behind FortiGate that you are able to ping to an internet IP address without need for fragmentation. From windows command prompt, you may run the below command and check,
c:\> ping -l 1472 8.8.8.8 -f
best regards,
Jin
Created on 03-07-2025 11:43 AM Edited on 03-07-2025 11:43 AM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi Jin,
Thanks for the reply. I ran this command and the response times look normal. We ended up factory resting another 60E, putting in the static IP and static route, and trying that. It still wouldn't get more than 10MB down. We tested with a laptop and got the same results.
We're going to back to ATT and this now looks like an issue on their end. I will update the post once we know more.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Based on the details provided, here are some troubleshooting steps and considerations that might help isolate and resolve the issue:
1. Verify Hardware Acceleration and Offloading
Hardware Acceleration:
Ensure that features like NAT offloading or hardware acceleration are enabled (or, in some cases, disabled) as per the firmware recommendation. Fortinet devices often rely on these to achieve full throughput.
Flow-based vs. Proxy-based Inspection:
Check if the firewall is operating in flow-based mode, which is generally faster for high-throughput scenarios.
2. Check Interface Settings and Duplex Modes
WAN Port Duplex/Speed:
Although you mentioned testing 100full and auto negotiation, it’s good to double-check that the WAN interface is negotiating correctly with ATT’s equipment. Some mismatches might not show as errors but can limit throughput.
MTU Settings:
Verify that the MTU on the WAN interface matches what ATT requires. A mismatch here could impact large download performance.
3. Policy and Deep Inspection Considerations
Policy Order and Settings:
You’ve already tried a bare-bones policy, which is a good step. Ensure that no other hidden policies or security profiles (like deep packet inspection, antivirus, or web filtering) are unintentionally slowing down the download path.
SSL Inspection: If SSL inspection is enabled, try bypassing it temporarily to see if it affects throughput.
4. Firmware and Hardware Alternatives
Firmware Version: Since you’re on Fortiwifi 60E firmware 7.2.10, check if there are any known issues with this version regarding throughput, or if a firmware upgrade/downgrade might resolve the issue.
Hardware Variance:
The fact that a direct laptop connection achieves 45MB down suggests the issue is indeed between the ISP and the firewall. It might be worth confirming that both the FortiWifi 60E and 60F units are configured identically regarding acceleration and inspection features.
5. ISP and Equipment Chain
Bypass Testing:
As ATT noted that removing the firewall “fixes” the issue, consider testing with a transparent bridge mode (if available) or a bypass setup to see if any specific packet handling by the firewall is causing the slowdown.
Logs and Diagnostics: Check firewall logs or run diagnostics (like packet captures) on the WAN interface. Look for signs of dropped packets or retransmissions that could indicate issues with the firewall’s handling of inbound traffic.
6. Engage with Support
Fortinet Support:
Since Fortinet technicians have already reviewed the configuration, consider asking if there’s any known incompatibility or performance tweak specifically for ATT fiber setups.
ISP Collaboration:
Keep your ISP in the loop, as they may need to review any potential QoS or session handling settings on their end, even if they have claimed that the issue disappears when the firewall is removed.
By systematically testing these areas, you can narrow down whether the issue stems from the Fortinet device’s configuration, firmware quirks, or interaction with ATT’s equipment. Each of these steps has the potential to unearth a setting that could be throttling the download speed despite the upload performing as expected.
Let me know if you need further details on any of these steps or if there’s any other information I can provide!
