Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Not applicable

FG-60 Stops Passing Traffic

I' m at my wits end and I' m hoping you guys can help out with a problem that I' ve got. We have deployed a couple of FG-60s and are now having problems with the devices. The first sign of trouble was when a client complained of not having Internet access (port 80). We were running MR-6 at the time. If I reset the device traffic would start to flow again. After this happened a couple of time, I called the support number for assistance. I was asked to upgrade to MR-7 which I did. We then started having occasional problems at the same client with POP3 access. Again, a reset on the device cleared the matter. Today, we experienced problems at our colo site (big problems here) with accepting POP3 traffice on an FG-60 with MR-6 installed. It' s not like we' re lighting up the devices with activity but I cannot continue resetting the devices to get things going again. It appears that the device just stops accepting/forwarding traffic. Does anyone have any ideas abou what' s happening?? I' m ready to pull the devices and install something that won' t fail in this manner. Any help is appreciated.
35 REPLIES 35
Not applicable

Soeren, I don' t have many users behind the device, but after sending my config to FortiGate support, they told me to have possibly too less memory for my needs. I' m using many features, primarily policies, AV and NIDS, along with extensive logging and HTTP/POP3/SMTP scanning features. And I' m using 2.50/MR6. 2.80 wouldn' t be supported, I guess, due to the lack of memory. They also suggested me to switch some features off that I don' t really need, but why should I purchase a FortiGate if I can' t use all of its features altogether? So switching to a FG-60 seemed to be the way... until I read these postings. Michael
Not applicable

Hi All, Well, we replaced all of the FG-60s that we had deployed and everything seems to be working well with our SPARC based SunScreen firewall in our colo and cheap Netgear at our remote sites. I do miss the anti-virus. We' ve setup a test lab where we' ll be driving different levels of traffic through the devices to provide more info to the Fortinet engineers. BTW, there is a new maintenance release but no release notes. Has any brave soul tried tis and if so what we' re the results?
Not applicable

I have two FG-300' s that are on MR7 and not experiencing any problems passing traffic.
Not applicable

[Deleted by Admins]
skyhigh
New Contributor

ORIGINAL: slayer I hope Fortinet people are reading all our posts and hope they shed light to some of our questions... it seems like we' re the only onces answering questions.
Reading ... yes. Answering questions ... rarely. This is a user forum. If you have a technical support question for Fortinet technical support, please open a ticket with us through the normal channels (e-mail or phone).
Fortinet Technical Support
Fortinet Technical Support
Not applicable

WHAT???
Not applicable

Hi All, Initial testing of the FG200 has proven very interesting: Approximately 50% of my service traffic is now being passed through the FG200. It’s hardly registering on the CPU usage…!!! Internal -> External performance is lightning speed…!!! (Better than I ever got on the FG60) I shall be moving the remainder of my services over tonight and will let you know how it goes… Regards, Kevin…
Not applicable

Hello All, (Again) My FG200 is now fully installed and it’s working perfectly… Average CPU / Memory usage is less than 25%; the performance is outstanding to the point that I have received calls from several of my customers who have noticed the difference. Alex mentioned in an earlier post that the FG200 supported 802.1q VLANs… In my original specification I needed 3 local networks and was therefore considering the FG400 but the price was just too high. I have an old 3Com 3300 switch that was mothballed (noisy fans) I reconfigured this for 3 VLANs, connected it to the DMZ port and it works a treat… All in all it looks like the best solution for me was to upgrade to the FG200 however, on specification, the FG60 should have done the job. It is my opinion that too many features are available on the FG60 and the CPU / Memory configuration is just not up to the job, especially if you are providing services behind the firewall. The FG60 may well be perfect as an office connectivity router but not if you need to run any services. One other comment, I am using SSH Sentinel for VPN access through the firewall, with only one client connecting through the FG60 it was slow and not that reliable, through the FG200 there is virtually no degradation in performance and so far it has connected every time. I would like to thank every contributor to this forum and hope that you all find a solution to this problem. All of your comments have helped me to resolve the problems here. Many Thanks to you all, Regards, Kevin Vahn Gill
Not applicable

Kevin, I was wondering how many users you have going through the FG-200 and what services you have lit up. I am asking because I have run into problems scanning inbound HTTP traffic with the session starting from the user. Spikes the CPU usage in the FG-100 and now I have seen it happen again in a FG-1000 demo I am doing. Thanks
Not applicable

Hi Scott, Internal Users = 6 Servers & 5 Workstations. Server 1 = (HTTP, FTP, SMTP & POP3) Server 2 = (HTTP, FTP, SMTP & POP3) Server 3 = (Jabber & FTP) Server 4 = (HTTP, FTP & 2 Custom Services) Server 5 = (SMPT, POP3 & Jabber) Server 6 = (12 Custom Services) Server 1 & 2 average 6000 web hits/hour each (24hrs) Server 1 & 5 average 3000 total emails per day (8am – 6pm) NDIS Enabled on External Interface AV Enabled on ALL Incoming Traffic Using Port Forwarding on all services, only about 12 public IP’s in use. Running 3 VLANS on DMZ Interface via 3Com 3300 Switch Average CPU ~ 24% & Average Memory ~32% Sessions usually between 200 & 600 on 5 second update… ALL (YES ALL) of the problems I had with the FG60 have gone completely. It got to the stage that I was having to reboot the unit 1-2 times a day, 3 times in one week I had to reboot it in the early hours (2am – 4am, I was not happy) The 3 VLANS are test only so their is hardly any traffic on them, During the day only one workstation is in use, mine… when the kids get home then they start using some bandwidth. Hope that helps, any questions please don’t hesitate to contact me. Regards, Kevin… Email: Kevin@gillns.com
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors