Hi everyone,
I have a Fortigate 30E and zyxel GS1900 switch in my office.
We have two VLANs and the routing is 'Router on a Stick' mode.
Recently we found the inter-VLAN is slower than speed inside the same VLAN.
Here are our test results using iPerf3 (using NAS as the iPerf server to do speed test)
We are wondering it is a routing problem. Could you please advise what we can do to improve the inter-VLAN connection speed?
Thank you.
Solved! Go to Solution.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
The link aggregation may help to increase the throughput in case you don't apply any security feature for that traffic. For the Fortigate model you can refer to this matrix and choose one of the new models that have support for "Virtual Hardware Switch".
Same VLAN communication is done through the switch that usually works in wire speed so it can not be compared directly. Since you are using an entry level of the FGT family I guess you are reaching its limits. Kindly refer to the Datasheet of this product to have a better understanding of the capabilities of this model and the features that may have been enabled that may affect the overall throughput. This doesn't look like a routing problem.
Regarding the point 3 that should be investigated on the WiFi part and the connection speed of the end host.
Thanks ebilcari.
Actually VLAN1 is the default 'hardware switch' lan. And our VLAN3 is attached to the 'hardware switch' lan. See below screen shots.
Will it be helpful (increase connection speed) by attaching VLAN3 to wan interface?
Or will it be helpful if I use link aggregation to connect Fortigate and our GS1900 switch (making the stick b)?
If both above will not work, could you advise us what model of Fortigate should we use to improve the inter-VLAN speed?
Thank you.
The link aggregation may help to increase the throughput in case you don't apply any security feature for that traffic. For the Fortigate model you can refer to this matrix and choose one of the new models that have support for "Virtual Hardware Switch".
Thank you for the repy.
I have further questions.
When creating VLANs, will there be any differences attaching the VLAN to different interfaces (wan interface or lan interface)?
Thank you.
The VLAN can be created under interfaces but remember that it will function as a sub interface not as VLAN spanning. Kindly refer to this article that shows many types of configurations and the use cases.
I have the same problem thank you for these valuable insights.
You can try remove all security profiles from the related policy and redo the test.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1662 | |
1077 | |
752 | |
443 | |
220 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.