We're facing an issue where traffic shaping on our FortiGate 60F device doesn't seem to be working as expected.Despite setting up the necessary configurations, no traffic appears to be shaped — the system always shows strange current-bandwidth (diagnose netlink interface list) when monitoring shaping statistics. Same configurations works well on Fortigate 100E. At same time shared shaping and per-ip shapers works as expected on Fortigate 60F.
The only thing that makes shaping profiles work on Fortigate 60F is disabling ASIC Offloading in the relevant firewall policy. But we wouldn't want to do that because all the traffic would go through the CPU.
FortiOS version 7.2.9 - 7.2.11
The real upload bandwidth is about 8 Mbps, but the system shows as 27kbps
Hi @mchupin
The FortiGate 100E and 60F models use different NPU drivers. I will investigate your case and try to reproduce it in my lab.
Could you please share some additional information to help with troubleshooting?
I’m Bill from Fortinet. If possible, please send the details to my email: bhoang@fortinet.com.
1- Configuration (it is very helpful if I try to reproduce the same configuration with you, if fact all things are same is perfect)
2- dia sys session list ( the session related to traffic you want to set QOS)
3- Output of NPU commands :
diagnose npu np6xlite dce 0
diag npu np6xlite anomaly-drop 0
diag npu np6xlite sse-stats 0
diag npu np6xlite session-stats 0
Regards
Bill
User | Count |
---|---|
2551 | |
1356 | |
795 | |
646 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.