Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
zoriax
Contributor

FortiGate WAN Latency

 

Hi everyone,

 

I could use some help today. We're experiencing some unusual WAN latency issues.

 

We have a setup using a pair of FortiGate-120G and FortiGate-100F devices with a WAN configured in LACP with 2x1Gb links. The network connection is structured as follows:

 

WAN ISP (LACP 2x1Gb) <----> 120G (in Transparent mode on VDOM) <----> 100F <----> LAN

When our WAN traffic increases, we notice a rise in latency, particularly visible with ping probes. Could this be an issue with the ISP, a security profile, or something related to NPU offloading or ASIC processing?

 

Thanks

2 REPLIES 2
johnathan
Staff
Staff

I would assume that you would be able to ping towards the internet on each hop to see where the latency actually lies. For example, if you are able to ping with good latency while the issue is occurring on the 120G, it is probably not the ISP and is either that device or something downstream causing the issue.

Depending on what security features you have enabled and what inspection mode the policies are in, it can introduce some more latency. Are you able to show us the relevant policies on the 120G and 100F? 

"Never trust a computer you can't throw out a window."
zoriax
Contributor

Hi Johnathan,

 

Thanks for your response. After some test, if I reduce the bandwidth around 500Mbps the latency is now "normal". Between my environnement and my FAI, I have two 1GB link with copper (connected on 10Gb switches). I suspected the copper medium to be the bottleneck because latency is high when traffic reach 1Gb on one interface.

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors