Hi everybody
I have a Fortigate 80C connected to Wan1 a pppoe services and Wan2 to MPLS with Router cisco, and the FW is in mode NAT,
I have 5 VLANs managed by the FW, with a routing table for to reach the intranet sites through MPLS, apparently all works without problem, internet, ping, tracert, nslookup, all services, the navigation in internet is OK, but the problem that I have is when I try to reach the page through the MPLS take a long time to load it 5 or 10 minutes, but I have detected that this only occur when the devices are connected to 1GB, because the devices that have network card to 100MB or use the Wifi to 130 MB works very well, in fact I have modified the speed in the port of the Switch to make a test and works without problem.
I have verified the interface in the FW, make a sniffer, but is not clear for me because only I have this issue with 1GB speed.
Somevary else know if I need to make some changes in the FW to avoid this problem.
As you can see in the diagnostic of the WAN2 don't see any problem
FGT80C # diagnose hardware deviceinfo nic wan2
Driver_Name iegbe
Driver_Version 0.8.0-NAPI
PCI_Vendor 0x8086
PCI_Device_ID 0x5044
PCI_Subsystem_Vendor 0x0000
PCI_Subsystem_ID 0x0000
PCI_Address 5:1.0
PCI_Bus_Type PCI Bus #05
PHY_Type 3
MAC_Type 8
IRQ 0
System_Device_Name wan2
Current_HWaddr 00:09:0f:ef:bf:27
Permanent_HWaddr 00:09:0f:ef:bf:27
Link up
Speed 1000
Duplex full
State up(0x1203)
MTU_Size 1500
Rx_Packets 117092
Tx_Packets 123510
Rx_Bytes 96670497
Tx_Bytes 15232733
Rx_Errors 0
Tx_Errors 0
Rx_Dropped 0
Tx_Dropped 0
Multicast 398
Collisions 0
Rx_Length_Errors 0
Rx_Over_Errors 0
Rx_CRC_Errors 0
Rx_Frame_Errors 0
Rx_FIFO_Errors 0
Rx_Missed_Errors 0
Tx_Aborted_Errors 0
Tx_Carrier_Errors 0
Tx_FIFO_Errors 0
Tx_Heartbeat_Errors 0
Tx_Window_Errors 0
Thanks a lot for your help
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
As far as I can guess there are 2 reasons:
1- the cable between WAN2 and the Cisco router is broken
2- the Cisco router port doesn't negotiate well, either speed or duplex or polarity
For 1-, change the cable to a proven new one. For FE only 4 of the 8 wires are used, for GE you need all 8.
For 2- temporarily put a 100/1000 switch in between which is capable of buffering traffic.
Maybe these simple tests will give you more hints where to locate the source problem. I don't think MTU is an issue here as it would have been reflected in the port error statistics. BTW, you should check the error stats of the Cisco port as well.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1660 | |
1077 | |
752 | |
443 | |
220 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.