Hi,
I am current running 6.4.4 with 60F in profile-based mode. the policy and the web filter profile are both in Flow mode. And I only use Certificate-inspection.
I have noticed, If I enabled any "Fortiguard Category" in the web filter profile. then when I test with speedtest etc. I get 70% performance hit every time. I can understand 30% hit of AV profile since it need look into the the contents even it's not decrypted. But I assume Web filter with certificate-inspection, only look into CN in the handshake and of course none SSL traffic. Looks like the speedtest is none SSL traffic. Is those kind of performance impact normal? If I run web filter in monitoring only mode. the performance hit is almost Zero. Thanks.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1740 | |
1108 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.