Hi,
the following setup is done:
Site a: Fortigate 201F, running VLAN, with a transfer net
Site b: Fortigare 401 F, running the same like above, between, 10 GBit Layer2 Link (600 km range, German network provider)
Running iperf (Speedtest) site to site, we have around 1.38 GBits/second, this is awful.
Running a download/upload test site 2 site, ends up in 200 - 220 mb/s.
Running iperf from site to site without Fortigate, speed is about 9 Gbits/second, so, it is not a fault on the Layer2 connection.
We did the same setup with a second 201F we have in stock, same problem, same speed.
We tried with FortiOS 7.0.15, 7.4.4 and 7.2.8, same results.
Because no filters are in place, I can just imagine, NAT rules (Nat pooling) is the problem maybe, because we need this to reach the networks, and this may harm the NGFW performance, which, if I read the datasheet correctly, is max. at around 3,5 GBit.
Is the performance of the Fortigate 201F really so f***** slow?
I read other reports, and this ends up in the idea, that the 201F is the problem.
2nd problem we mentioned,
creating a Fortilink on X1/X2, with *SAME* config like on X3/X4, ends in packetloss. Tested also with above mentioned 3 different FortiOS versions and also with 2 different 201F.
This is a nightmare!
Best
Ronny
The performance issue you're experiencing with the Fortigate 201F and 401F, especially the significant speed drop when using the devices, suggests that the Fortigate 201F may indeed be the bottleneck. Here are the key points to consider:
Performance Limitation: The Fortigate 201F has a maximum throughput of around 3.5 Gbps for firewall traffic. Your observed speed (1.38 Gbps) indicates that the device is underperforming even below its advertised capability. NAT processing could be contributing to this performance degradation.
FortiLink Issues: The packet loss on Fortilink interfaces (X1/X2 vs. X3/X4) despite having identical configurations could point to hardware or firmware inconsistencies. This might also indicate potential issues with specific interfaces on the Fortigate 201F.
Alternative Testing: Since your speed without the Fortigate devices reaches 9 Gbps, it's clear that the Layer2 connection is not the issue. The problem lies with the Fortigate devices' handling of the traffic.
The Fortigate 201F's performance in your setup seems to be the limiting factor, and further investigation or hardware upgrade may be required to achieve desired speeds.
Hi,
can it be possible, that the 201F Modell or 200 series, are not possible to reach out 10 Gbps in *one* stream?
Using 8 streams in parallel, I can reach out nearby 10 Gbps, single Stream is limited to around 1,35 Gbps.
Thanks for any tip.
Ronny
------------------------------------------------------------
Client connecting to 10.240.4.140, TCP port 5001
TCP window size: 748 KByte (default)
------------------------------------------------------------
[ ID] Interval Transfer Bandwidth
[ 10] 0.0000-10.0017 sec 3.29 GBytes 2.82 Gbits/sec
[ 7] 0.0000-10.0047 sec 1.18 GBytes 1.01 Gbits/sec
[ 9] 0.0000-10.0105 sec 1020 MBytes 854 Mbits/sec
[ 3] 0.0000-10.0051 sec 788 MBytes 661 Mbits/sec
[ 6] 0.0000-10.0097 sec 577 MBytes 483 Mbits/sec
[ 5] 0.0000-10.0099 sec 1.94 GBytes 1.66 Gbits/sec
[ 8] 0.0000-10.0077 sec 1.21 GBytes 1.04 Gbits/sec
[ 4] 0.0000-10.0104 sec 975 MBytes 817 Mbits/sec
[SUM] 0.0000-10.0106 sec 10.9 GBytes 9.35 Gbits/sec
[ CT] final connect times (min/avg/max/stdev) = 7.835/8.098/8.278/3.040 ms (tot/
It is the same nightmare like it here:
https://www.reddit.com/r/fortinet/comments/xvad5m/200f_poor_performance/
It seems, it has never been resolved so far.
@gfleming seems like similar like: Slow iPerf (and generall traffic) through firewall - Page 2 - Fortinet Community
At Site A, we’re using a Fortigate 201F configured with VLANs and a transfer network, and at Site B, a Fortigate 401F with a similar configuration. These sites are linked via a 10 GBit Layer 2 connection spanning 600 km, provided by a German network provider. However, iperf tests between the sites through the Fortigates disappointingly cap at around 1.38 GBits/second. Direct tests without the treewisemen Fortigates achieve 9 Gbits/second, so the issue clearly lies with the Fortigate devices.
@CollinFord can you please write me a PM that we can exchange our knowledge, and to debug deeper maybe together? Thanks a lot, Ronny
Hi,
I wonder if you managed to make progress on this issue.
I have a Fortigate 200F with a new internet connection connected to port X3 via 10Gbps SFP and connected directly to the operator's router.
Speed test using PC connected directly to the router (without going through the firewall) --> 950 Mbps download / 700 Mbps upload
Speed test using PC connected to the firewall (without UTM policies) --> 900 Mbps download / 40 Mbps upload.
Using FortiOS 7.2.10
Thank you!
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1737 | |
1107 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.