Hello Guys,
Good day.
We have an issue in our school. Our internet speed slows down during school hours, but after office hours it will go back to normal speed. I keep calling the ISP provider thinking that they have an issue. But when they test their router and removing our Firewall plugged to their router. The speed is ok. According to their technical support check the settings of our firewall.
I just need an advise how to prove to my superior that this is really indeed an issue with our FG100D firewall.
I hope you can give me advise regarding this issue.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Welcome to the forums.
Before you pull out your hair, have you tested what the load is during hours? Perhaps you are near saturation. Please let the community know what troubleshooting steps have been taken so far.
Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com
Soound more like the ISP and the network is load-shard and saturated. What type of internet is being provided? DSL, VDSl, Cable-modem,etc.....
Also when they tested the router, was it during the same business hour? I would do the simple test and look at any link-errors and also anything infected on the wire.
PCNSE
NSE
StrongSwan
I'd say it's not totally unconceivable that the FGT is underpowered.
1- How many users and how many sessions do you see during 'slow' phases?
2- Do you apply the full UTM set, like AV, IPS, AC,...? For instance, if you just apply IPS and enable all available signatures it might kill nearly any size model.
3- Who has configured the FGT and the UTM features in particular? Sufficient background? His/her response to your complaints? Have you measured the vital parameters of the FGT during heavy load, such as # of sessions, free memory %, CPU load %?
Hello emnoc
Thank you for your reply.
IT is a DSL connection. Tested the router during school hours. Problem is she only has the access to the FG.
Tested the router by removing the FG connection. Comparing both results which is if FG connection is remove ISP is ok and the FG connection was put back our speed will massively goes down.
Hello ede_pafu
Thank you for your reply
[ol]I also contacted my superior just to have check just to be sure. But have no response
Hello Guys,
Thank you for all the replies. It was fixed already.
The only thing I know what was change on FG was youtube was blocked due to overloading. The other ISP was activated again. The rest of the changes I am no sure due to have no access. Let just say that there is something happening inside the firewall. It takes time for my superior to notice it.
Thank you very much for you help.
I really appreciate it.
Good to know they've fixed it (kind of), thanks for the follow-up.
As FortiOS is a complex operating system it is possible to misconfigure it which might cause slow-downs. Maintenance/operation should really be left to a professional. Contrary to a common misbelief a security configuration is never static, it needs to be monitored and adapted from time to time.
The better questions is: Why isn't the one who is managing the Fortigate on these forums?
Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1713 | |
1093 | |
752 | |
447 | |
231 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.