Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
RoBau
New Contributor

Internet Speed Problems with FG80D and 5.6.2

Hello,

 

we are a MSP with Fortigate Firewalls. One customer now has bis internet bandwith problems with his firewall FG80D and FW 5.6.2 in his office in Rumania. The problems started like 2-3 weeks ago, before everything worked just fine (VPN connection/ UTM Features). Their internet access should be almost 500MB/250MB but rigth now behind the FW they have not more than 20 MB DOWN and 40MB UP (which is really strange).

 

We were sure that this just can be a ISP problem since we didnt change anything on this firewall for months. Since we dont have people on site we checked with their IT support team. They met 2 times last week to check the line and these are the results:

> ONE PC behind the firewall in LAN and WAN connected to Fiber Router (normal status): not more than 20MB/ 40MB

> Same PC behind directly (with same IP configuration as fw) to the router: > 300 MB/ 250MB

> Same PC behind another Router with same configurtion WAN and LAN (as firewall): same results > 300MB/ 250MB

 

They are not more than 20-30 people in the office. FW memory is never higher than 60% and CPU is really low. Sessions are really normal and when everybody is working we dont see anything unusual. We tried to desactivate all UTM features in the policies and nothing. We opened a ticket with Fortinet but nothing sofar.

 

Having these results we really think that this can be a FG issue. We dont have any information if the ISP changed something in their network (MTU, etc.). We can exclude problems with switches, routers, PC problems, etc.

 

Any idea what we can do, we really didnt have this kind of problems with all other firewalls and since we dont have technicians there it is getting really complicated.

 

Thanks a lot for any help!

 

 

9 REPLIES 9
omega
New Contributor

Strange. We are chasing a similar Problem for days no and got no feedback from Fortinet so far.

We are quite sure that everything has been fine a few weeks ago and there is no difference in our config.

 

In our case the issue only occurs when there is concurrent traffic on different interfaces. E.g. User connects to a proxy in dmz and that proxy fetches from internet on wan1.

Throughput drops to 6MB/s on a 60D and to 10MB/s on a 60E.

 

You seem to have tested direct internet access over the fortigate?

No changes in config (for logging etc.)?

Ashik_Sheik
Contributor II

Was this issue immediately after placing FGT in between or was working fine for a while and started this issue ?.Give us more details .

 

I believe there may b configuration issue .Check if any traffic shaping is applied .After 5.4 may b traffic shaping rules are not under IPV4 .

 

If the firmware is old kindly upgrade and check.

 

Regds,,

 

Ashik

Sheik Mahammad Ashik
Sheik Mahammad Ashik
RoBau

Hi,

 

FG80D was working fine for more than 1 year, everything the same, ISP, connection, etc. Last time we changed something was upgrading to 5.6.2 (Firmware should be OK) in June 2018, since than no changes at all. One policy, but it should not affect at all.

 

Again, behind the router with same PC they get over 300MB download. Once behind the FG right now we just get max. 18-20MB download.

 

Traffic shaping should not be configured, I didnt configure the FW myselfe but there is no need for it and I dont see it in the configuration.

 

Thanks!

Ashik_Sheik

Strange but without traffic shaping policy , it is nearly impossible FGT to limit bandwidth .

 

You can try to create new policy and move the policy on the top without any filters or security profiles with source NAT and filter one source address and check the speed on the filtered machine .

 

Regds,

 

Ashik

Sheik Mahammad Ashik
Sheik Mahammad Ashik
RoBau

Hi,

 

this is getting really crazy. Fortinet moved the ticket to another level (we checked diagnos the ports and everything is OK) and since 2 days nothing new from their site. 

 

I just put one PC in one dedicated policy on top with no UTM filtering and same results. I played with the MTU size from 1300 to 1500 and no results. I changed to flow based and nothing.

 

Any more ideas? Right now I dont trust them anymore on their site, maybe their tests were not correct. That really seems like a big ISP thing.

Thanks!

Ashik_Sheik

Looks like some bug in the firmware .Try to upgrade to 5.6.5 and check

 

Regds,

 

Ashik

Sheik Mahammad Ashik
Sheik Mahammad Ashik
RoBau

Hello,

 

I have been contacted from the Fortinet Support and we did like 3 days testing and checking with no results sofar. I did do also an update but no results. 

 

This is so strange. I am only thinking about resetting the firewall and check but this would be more than strange.

 

Any other ideas?

 

Thanks!

rwpatterson
Valued Contributor III

Perhaps the ISP swapped gear and there is an compatibility issue. Also have you tried (from on site!) messing with the auto/fixed speeds and duplex settings?

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
Ashik_Sheik

Try configuring ISP link to another interface and check ..This is silly but may b port issues .

 

 

Sheik Mahammad Ashik
Sheik Mahammad Ashik
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors