- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Inter VLAN routing
Hi everyone,
I have a Fortigate 30E and zyxel GS1900 switch in my office.
We have two VLANs and the routing is 'Router on a Stick' mode.
Recently we found the inter-VLAN is slower than speed inside the same VLAN.
Here are our test results using iPerf3 (using NAS as the iPerf server to do speed test)
- From PC in VLAN3 to NAS in VLAN3: 950M
- From PC in VLAN1(wired) to NAS in VLAN3: 550M
- From PC in VLAN1(WiFi) to NAS in VLAN3: 350M
We are wondering it is a routing problem. Could you please advise what we can do to improve the inter-VLAN connection speed?
Thank you.
Solved! Go to Solution.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
The link aggregation may help to increase the throughput in case you don't apply any security feature for that traffic. For the Fortigate model you can refer to this matrix and choose one of the new models that have support for "Virtual Hardware Switch".
If you have found a solution, please like and accept it to make it easily accessible for others.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Same VLAN communication is done through the switch that usually works in wire speed so it can not be compared directly. Since you are using an entry level of the FGT family I guess you are reaching its limits. Kindly refer to the Datasheet of this product to have a better understanding of the capabilities of this model and the features that may have been enabled that may affect the overall throughput. This doesn't look like a routing problem.
Regarding the point 3 that should be investigated on the WiFi part and the connection speed of the end host.
If you have found a solution, please like and accept it to make it easily accessible for others.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thanks ebilcari.
Actually VLAN1 is the default 'hardware switch' lan. And our VLAN3 is attached to the 'hardware switch' lan. See below screen shots.
Will it be helpful (increase connection speed) by attaching VLAN3 to wan interface?
Or will it be helpful if I use link aggregation to connect Fortigate and our GS1900 switch (making the stick b)?
If both above will not work, could you advise us what model of Fortigate should we use to improve the inter-VLAN speed?
Thank you.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
The link aggregation may help to increase the throughput in case you don't apply any security feature for that traffic. For the Fortigate model you can refer to this matrix and choose one of the new models that have support for "Virtual Hardware Switch".
If you have found a solution, please like and accept it to make it easily accessible for others.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thank you for the repy.
I have further questions.
When creating VLANs, will there be any differences attaching the VLAN to different interfaces (wan interface or lan interface)?
Thank you.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
The VLAN can be created under interfaces but remember that it will function as a sub interface not as VLAN spanning. Kindly refer to this article that shows many types of configurations and the use cases.
If you have found a solution, please like and accept it to make it easily accessible for others.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I have the same problem thank you for these valuable insights.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
You can try remove all security profiles from the related policy and redo the test.
