Hello,
we are a MSP with Fortigate Firewalls. One customer now has bis internet bandwith problems with his firewall FG80D and FW 5.6.2 in his office in Rumania. The problems started like 2-3 weeks ago, before everything worked just fine (VPN connection/ UTM Features). Their internet access should be almost 500MB/250MB but rigth now behind the FW they have not more than 20 MB DOWN and 40MB UP (which is really strange).
We were sure that this just can be a ISP problem since we didnt change anything on this firewall for months. Since we dont have people on site we checked with their IT support team. They met 2 times last week to check the line and these are the results:
> ONE PC behind the firewall in LAN and WAN connected to Fiber Router (normal status): not more than 20MB/ 40MB
> Same PC behind directly (with same IP configuration as fw) to the router: > 300 MB/ 250MB
> Same PC behind another Router with same configurtion WAN and LAN (as firewall): same results > 300MB/ 250MB
They are not more than 20-30 people in the office. FW memory is never higher than 60% and CPU is really low. Sessions are really normal and when everybody is working we dont see anything unusual. We tried to desactivate all UTM features in the policies and nothing. We opened a ticket with Fortinet but nothing sofar.
Having these results we really think that this can be a FG issue. We dont have any information if the ISP changed something in their network (MTU, etc.). We can exclude problems with switches, routers, PC problems, etc.
Any idea what we can do, we really didnt have this kind of problems with all other firewalls and since we dont have technicians there it is getting really complicated.
Thanks a lot for any help!
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Strange. We are chasing a similar Problem for days no and got no feedback from Fortinet so far.
We are quite sure that everything has been fine a few weeks ago and there is no difference in our config.
In our case the issue only occurs when there is concurrent traffic on different interfaces. E.g. User connects to a proxy in dmz and that proxy fetches from internet on wan1.
Throughput drops to 6MB/s on a 60D and to 10MB/s on a 60E.
You seem to have tested direct internet access over the fortigate?
No changes in config (for logging etc.)?
Was this issue immediately after placing FGT in between or was working fine for a while and started this issue ?.Give us more details .
I believe there may b configuration issue .Check if any traffic shaping is applied .After 5.4 may b traffic shaping rules are not under IPV4 .
If the firmware is old kindly upgrade and check.
Regds,,
Ashik
Hi,
FG80D was working fine for more than 1 year, everything the same, ISP, connection, etc. Last time we changed something was upgrading to 5.6.2 (Firmware should be OK) in June 2018, since than no changes at all. One policy, but it should not affect at all.
Again, behind the router with same PC they get over 300MB download. Once behind the FG right now we just get max. 18-20MB download.
Traffic shaping should not be configured, I didnt configure the FW myselfe but there is no need for it and I dont see it in the configuration.
Thanks!
Strange but without traffic shaping policy , it is nearly impossible FGT to limit bandwidth .
You can try to create new policy and move the policy on the top without any filters or security profiles with source NAT and filter one source address and check the speed on the filtered machine .
Regds,
Ashik
Hi,
this is getting really crazy. Fortinet moved the ticket to another level (we checked diagnos the ports and everything is OK) and since 2 days nothing new from their site.
I just put one PC in one dedicated policy on top with no UTM filtering and same results. I played with the MTU size from 1300 to 1500 and no results. I changed to flow based and nothing.
Any more ideas? Right now I dont trust them anymore on their site, maybe their tests were not correct. That really seems like a big ISP thing.
Thanks!
Looks like some bug in the firmware .Try to upgrade to 5.6.5 and check
Regds,
Ashik
Hello,
I have been contacted from the Fortinet Support and we did like 3 days testing and checking with no results sofar. I did do also an update but no results.
This is so strange. I am only thinking about resetting the firewall and check but this would be more than strange.
Any other ideas?
Thanks!
Perhaps the ISP swapped gear and there is an compatibility issue. Also have you tried (from on site!) messing with the auto/fixed speeds and duplex settings?
Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com
Try configuring ISP link to another interface and check ..This is silly but may b port issues .
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1660 | |
1077 | |
752 | |
443 | |
220 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.