Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Aslumon
New Contributor

Fortigate 30E Packet loss

Dear Team,

We are experiencing a recurring issue with over 7 Fortigate 30 E devices, all of which have failed within a year's time span. The LAN connections on these devices are notably slow, and upon investigation, we have identified a significant amount of packet loss.

Unfortunately, we do not currently hold a support license, which limits our ability to seek assistance for these devices. Additionally, we have several more devices in operation, but given the pattern of failure, we anticipate they may encounter similar issues in the future. This poses a significant financial burden, as replacing these devices is costly.

We kindly request any assistance or guidance you can provide to address this situation effectively.

Thank you for your attention to this matter.

5 REPLIES 5
adambomb1219
SuperUser
SuperUser

What makes you think this is a hardware issue?  What is the LAN side?  What type of switch is the 30E connected to?  Why do you have no support?  How do you get OS and security updates?  What's the speed/duplex for the LAN side?  How exactly are you testing a "significant amount of packet loss"?

Aslumon

What makes you think this is a hardware issue? Reading several online docs i could find those are common for 30E devices.

What is the LAN side?
LAN side local network and A siste to site VPN established to HO.
Those are retail store which only have 5-6 devices.

What type of switch is the 30E connected to?
In the Wan we have terminated the ISP and from LAN we have connected an unmanaged switch for conneting the endpoints.. Why do you have no support?
Its for a small scale purpose and these devices where since more than ten years now.
How do you get OS and security updates? Never updated it yet.
What's the speed/duplex for the LAN side?
1 Gbps
How exactly are you testing a "significant amount of packet loss"?
From HO through the Site to Site VPN there isn't any ping drops to gateway but from the imternal network over there there is significant amount of packet drops.

 

adambomb1219

So you are having drops over the VPN tunnel?  How exactly are you testing this? Ping?  Is the bandwidth on the circuit saturated?  Is there packet loss directly to the internet?  Or is loss only over the VPN tunnel?  

So you have never updated your firewalls?  How do you solve vulnerabilities?  These are directly connected to the internet. Do these retail locations take credit cards? 

AEK
SuperUser
SuperUser

Hello @Aslumon 

I'll just give some recommendations as per my experience with such issues.

  • Always prefer auto negotiation (default) from both sides instead of fixed speed
  • Use minimum cat-5a cables for 1Gb links, but use minimum cat-6a if your device is in data centre (to resist to interference)
  • Prefer usage of factory made cables
AEK
AEK
hbac
Staff
Staff

Hi @Aslumon,

 

You can follow this article: https://community.fortinet.com/t5/FortiGate/Technical-Tip-Low-throughput-troubleshooting/ta-p/272657

 

I would suggest getting a support license and open a ticket with TAC to investigate the issue. If it is a hardware issue, you will be able to RMA it. 

 

Regards, 

Labels
Top Kudoed Authors