Hi Everyone,
We've been struggling with this for a couple months now. I'm wondering if anyone has even had a similar issue like this. This location switched to ATT fiber a few months ago. Right from the start we've never been able to get more than 10MB down when running speed tests. They have a 50/50MB connection. The bandwidth monitor on the status page also confirms download never getting above 10MB. Upload gets up to the mid 40s during speed tests every time.
We connected a laptop directly to ATTs equipment, ran a speed test and get 45ish down as expected. Naturally we've been treating this as a firewall config issue up to this point. Here's a list of everything we've tried so far
Apologies for the wall of text. I apricate any suggestions. If any one wants any further information I'll happy to provide it.
Hi,
If fragmentation is induced, then most likely we achieve lower throughputs
Please check from the host behind FortiGate that you are able to ping to an internet IP address without need for fragmentation. From windows command prompt, you may run the below command and check,
c:\> ping -l 1472 8.8.8.8 -f
best regards,
Jin
Created on 03-07-2025 11:43 AM Edited on 03-07-2025 11:43 AM
Hi Jin,
Thanks for the reply. I ran this command and the response times look normal. We ended up factory resting another 60E, putting in the static IP and static route, and trying that. It still wouldn't get more than 10MB down. We tested with a laptop and got the same results.
We're going to back to ATT and this now looks like an issue on their end. I will update the post once we know more.
Based on the details provided, here are some troubleshooting steps and considerations that might help isolate and resolve the issue:
1. Verify Hardware Acceleration and Offloading
Hardware Acceleration:
Ensure that features like NAT offloading or hardware acceleration are enabled (or, in some cases, disabled) as per the firmware recommendation. Fortinet devices often rely on these to achieve full throughput.
Flow-based vs. Proxy-based Inspection:
Check if the firewall is operating in flow-based mode, which is generally faster for high-throughput scenarios.
2. Check Interface Settings and Duplex Modes
WAN Port Duplex/Speed:
Although you mentioned testing 100full and auto negotiation, it’s good to double-check that the WAN interface is negotiating correctly with ATT’s equipment. Some mismatches might not show as errors but can limit throughput.
MTU Settings:
Verify that the MTU on the WAN interface matches what ATT requires. A mismatch here could impact large download performance.
3. Policy and Deep Inspection Considerations
Policy Order and Settings:
You’ve already tried a bare-bones policy, which is a good step. Ensure that no other hidden policies or security profiles (like deep packet inspection, antivirus, or web filtering) are unintentionally slowing down the download path.
SSL Inspection: If SSL inspection is enabled, try bypassing it temporarily to see if it affects throughput.
4. Firmware and Hardware Alternatives
Firmware Version: Since you’re on Fortiwifi 60E firmware 7.2.10, check if there are any known issues with this version regarding throughput, or if a firmware upgrade/downgrade might resolve the issue.
Hardware Variance:
The fact that a direct laptop connection achieves 45MB down suggests the issue is indeed between the ISP and the firewall. It might be worth confirming that both the FortiWifi 60E and 60F units are configured identically regarding acceleration and inspection features.
5. ISP and Equipment Chain
Bypass Testing:
As ATT noted that removing the firewall “fixes” the issue, consider testing with a transparent bridge mode (if available) or a bypass setup to see if any specific packet handling by the firewall is causing the slowdown.
Logs and Diagnostics: Check firewall logs or run diagnostics (like packet captures) on the WAN interface. Look for signs of dropped packets or retransmissions that could indicate issues with the firewall’s handling of inbound traffic.
6. Engage with Support
Fortinet Support:
Since Fortinet technicians have already reviewed the configuration, consider asking if there’s any known incompatibility or performance tweak specifically for ATT fiber setups.
ISP Collaboration:
Keep your ISP in the loop, as they may need to review any potential QoS or session handling settings on their end, even if they have claimed that the issue disappears when the firewall is removed.
By systematically testing these areas, you can narrow down whether the issue stems from the Fortinet device’s configuration, firmware quirks, or interaction with ATT’s equipment. Each of these steps has the potential to unearth a setting that could be throttling the download speed despite the upload performing as expected.
Let me know if you need further details on any of these steps or if there’s any other information I can provide!
User | Count |
---|---|
2588 | |
1380 | |
796 | |
658 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.