Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Auderas
New Contributor

FAP speed limit at 220Mbps

I have posted this question to r/Fortinet and to spiceworks, and so far no one has an answer for me.

 

First, I should state that I am a huge fan of Fortinet. We manage and recommend many of their products. Their firewalls are miles better in value and features than any I have seen. 

The APs though.... 

 

To summarize, all APs we have in production max out at around 220Mbps to the end clients (maybe 60 APs at different clients). I haven't tested the 421 series, but all others (regardless of model or release date) offer the exact same throughput. 

 

We have had 4 tickets open with support for APs that simply cannot produce bandwidths to the specifications of the devices. I have gone through the support calls, and even brought out an exact same spec AP from another manufacturer (6 antenna wave 2, 802.11ac max speed 1.3 Gbps release date 2012) to compare to their FAP321C. They cant help. It's maddening. They go through the checklist, and we see no improvement. I see a million different forum posts that are similar, and never reach any answer. 

 

[ul]
  • I am NOT looking to debug it. I have support for that, plus I've spend about 10 hours doing it, so I've probably tried what you want to suggest.
  • I AM looking to see if anyone out there is getting more than 220Mbps to a wireless client. If anyone can, I would love to hear from you. Then the we can sort out firmware version and config. I HOPE i am wrong, but so far I have found no one who can get past that 220Mbps speed limit.[/ul]
  • 3 Solutions
    tanr
    Valued Contributor II

    FAP 221E with 6.0.5 firmware (FP221E-v6.0-build0066) gives 303 Mbps with other devices connected in an area with a lot of RF noise and multiple interfering channels from neighbors.

    View solution in original post

    tanr
    Valued Contributor II

    Can you post more details about your config to clarify?  Along with firmware version and screenshots, details like:

     

    [ul]
  • Have you set the radio power manually (auto can be way off)?
  • Do you have power saving enabled (powersave-optimize under conf wireless-controller wtp-profile)
  • Are you using WiFi data channel encryption (DTLS) for the AC data channel (perf hit)?
  • Spectrum analysis on a radio? 
  • Have you disabled low data rates (see rates-11ac-ss34 at https://help.fortinet.com/fos60hlp/60/Content/FortiOS/fortigate-wireless/high-density-features.htm)
  • Using WIDS and if so with what enabled (ap-bgscan etc.)?
  • DARRP enabled?
  • Using DFS channels?
  • What broadcast suppression is enabled?
  • Are you using CAPWAP protected mgmt frames? [/ul]

     

     

     

  • View solution in original post

    tanr
    Valued Contributor II

    I'm managing FAPs from FortiGates, so you might not be able to change these settings.

     

    I've have had both speed and connection issues with some devices when PMF was enabled in the past (mainly older iOS and Apple devices).  CLI lets you set it to disable or optional per SSID (config wireless-controller vap).  Don't know how you get to it with cloud management.

     

    Regarding WIDS (https://docs.fortinet.com/document/fortigate/6.0.0/handbook/961129/wireless-intrusion-detection-syst...), I don't see it in the FortiCloud documentation, so don't know how it's handled for your case.  But some aspects of it, like scanning for rogue APs, could have perf hits, 

     

    I'm assuming that you have spectrum analysis off (under radio config for the wtp-profile) or you would see even worse performance.

     

    Have you tested with any non-FortiCloud managed FAPs?  Would be good to look at a default FAP 221E in bridge mode without cloud management to see if this might be a result of some setting on the cloud managed FAPs.

     

    Hoping that somebody with more WiFi knowledge than me jumps in here...

    View solution in original post

    28 REPLIES 28
    James_G

    Can you share fortiap profile on the managing fortigate Show the config under: config wireless-controller wtp-profile
    Auderas

    James_G wrote:
    Can you share fortiap profile on the managing fortigate Show the config under: config wireless-controller wtp-profile

     

    We use forticloud management. I can test it with fortigate management today, but I was told that in bridge mode it wouldnt matter.

     

    Auderas

    Yes, as I have mentioned before, I have spent hours and hours on this, with fortinet support. We have tested all channel widths, and set channels manually. We have also tested this at a location that we can confirm has no interference.

     

    TO recap, for anyone who is skimming the previous conversation, Ruckus, Aruba and Apple airstation, all with the same specs/gen all connect at close to spec (875Mbps or 1Gbps depending on the model). The FAP (three different models 221C 221E 321C, 4 different businesses, 11 different physical locations) all max out at 220Mbps. We do you forticloud for AP control, but each are in bridge mode.

     

    tanr
    Valued Contributor II

    FAP 221E with 6.0.5 firmware (FP221E-v6.0-build0066) gives 303 Mbps with other devices connected in an area with a lot of RF noise and multiple interfering channels from neighbors.

    James_G
    Contributor III

    I keep coming back to thinking 220mbps is about the limit for a 20mhz channel, can you use WiFi analyser to confirm channel bandwidth (I've got app on my Android phone)
    Auderas

    Yep, I use the same app. And yes, it's 80Mhz, you can see the width right there on the visualization. I like that thought process though!

    Auderas

    Another clue perhaps: I switched management to the fortigate from forticloud. Still in bridge mode. Same speed. I then changed it from 80Mhz to 40Mhz and saw the max speed drop from 220 to about 160Mbps, and I get about 130Mbps at 20Mhz width. So I'm sure we really are using the 80Mhz channel width, but something else is slowing it down. Again, we get full speed from wired and from similar hardware from other manufacturers.

    tanr
    Valued Contributor II

    Can you post more details about your config to clarify?  Along with firmware version and screenshots, details like:

     

    [ul]
  • Have you set the radio power manually (auto can be way off)?
  • Do you have power saving enabled (powersave-optimize under conf wireless-controller wtp-profile)
  • Are you using WiFi data channel encryption (DTLS) for the AC data channel (perf hit)?
  • Spectrum analysis on a radio? 
  • Have you disabled low data rates (see rates-11ac-ss34 at https://help.fortinet.com/fos60hlp/60/Content/FortiOS/fortigate-wireless/high-density-features.htm)
  • Using WIDS and if so with what enabled (ap-bgscan etc.)?
  • DARRP enabled?
  • Using DFS channels?
  • What broadcast suppression is enabled?
  • Are you using CAPWAP protected mgmt frames? [/ul]

     

     

     

  • Auderas
    New Contributor

    I have tried a million things, but if you have a config you want me to try I would SO appreciate it. As I said, we were mostly testing with forticloud management, which limited what we could change. Also, exporting our options was only possible with CLI at the AP rather than at the fortigate. 

     

    I do have a few answers for you. 

     

    We have used several firmwares, but all are now on 6.0 Build 0037

     

    We have set power manually without any improvement

    I have not set power-saving

    I have used both DTLS and Plan text, no improvement

    I have monitored the signal via a mobile app, but not anything with detailed reporting

    I have disabled low data rates, no affect

    Not sure about WIDS, is it set by default in forticloud?

    Tested with and without radio resource provision

    DFS channels are required to use 80Mhz Channel width

    I have only tried DHCP broadcast suppression. I will try more

    Protected Managment frames are required for 802.11ac. Are you saying there is a way to disable?

     

     

    tanr
    Valued Contributor II

    I'm managing FAPs from FortiGates, so you might not be able to change these settings.

     

    I've have had both speed and connection issues with some devices when PMF was enabled in the past (mainly older iOS and Apple devices).  CLI lets you set it to disable or optional per SSID (config wireless-controller vap).  Don't know how you get to it with cloud management.

     

    Regarding WIDS (https://docs.fortinet.com/document/fortigate/6.0.0/handbook/961129/wireless-intrusion-detection-syst...), I don't see it in the FortiCloud documentation, so don't know how it's handled for your case.  But some aspects of it, like scanning for rogue APs, could have perf hits, 

     

    I'm assuming that you have spectrum analysis off (under radio config for the wtp-profile) or you would see even worse performance.

     

    Have you tested with any non-FortiCloud managed FAPs?  Would be good to look at a default FAP 221E in bridge mode without cloud management to see if this might be a result of some setting on the cloud managed FAPs.

     

    Hoping that somebody with more WiFi knowledge than me jumps in here...

    Announcements

    Select Forum Responses to become Knowledge Articles!

    Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

    Labels
    Top Kudoed Authors