Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Ch_Hassii
New Contributor

FortiGate introducing Latency in Packet Flow

Hi, 

 

We are having 4201F in HA integrated with ACI. We see that traceroute is adding 20ms when trace land on FortiGate IP. 

Looking for opinions to minimize it. 

 

Thanks

6 REPLIES 6
johnathan
Staff
Staff

Are you able to elaborate a bit more on 'ACI' in this context? 
What do you have enabled on  the policies for this traffic?
What is the latency from the client to the FortiGate, and from the FortiGate to the server?

"Never trust a computer you can't throw out a window."
Ch_Hassii
New Contributor

Appologies, Can't draw it properly due to tight schedule. As we can see in the diagram below as soon as the trace lands on Fortigate response time jumpe to 35.398ms. 8th hope is FortiGate incoming Interface for this connection.  

T.PNG

 

rosatechnocrat
Contributor II

Can you post the configuration of the particular firewall policy that matches this traffic ? 

Rosa Technocrat --

Also on YouTube---

Please do Subscribe
Rosa Technocrat --Also on YouTube---Please do Subscribe
Ch_Hassii
New Contributor

Firewall Policy is allowing all with no security Controls applied 

 

config firewall policy
edit 6
set name "Primary>DR"
set uuid afcf94c4-6f4e-51ef-4a4b-866241348179
set srcintf "FW_Impct_L3_Out"
set dstintf "FW_Impact_L3_IN"
set action accept
set srcaddr "172.20.14.0/25" "172.20.10.128/25"
set dstaddr "172.24.5.0/25" "172.24.4.128/25"
set schedule "always"
set service "ALL"
set logtraffic all
next
end

Shashwati
Staff
Staff

Hello

Please collect packet capture (Wireshark) on Firewall and source and destination to see the traffic flow

  https://community.fortinet.com/t5/FortiGate/Troubleshooting-Tip-Packet-Capture-on-FortiOS-GUI/ta-p/1...

ujiunwo2
New Contributor

I had a similar case about 3 months ago, when I upgraded my fortigate 60f from 7.2.4 to 7.2.7 version. avg. response time jumped from 1ms to 50ms (in local network). Even fortinet support had trouble finding what was an issue, we tried firmware upgrade as our last resort. Upgrade solved the issue but we couldn't conclude what was the problem.

https://9apps.ooo/
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors