Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
sw2090
Honored Contributor

Issue with ASIC offloading and UTM on 100F Series?

After having done a load of testing I've come to the conlusion that there actually is an issue with ASIC offlading and UTM on the 100F Series.

This issue does not occur on 100E Series or a 300E or a 60F but it does on all of our 100F.

All FGT here are at 7.0.12.

 

Issue is:

 

When your internet policy is in flow mode (default) then per default ASIC offloading is on. If you then also applied some UTM Profiles or a security profile group to the policy you will notice that at least website that use http v2 protocol will no longer work. They will load endless or/and timout.

If you disable ASIC offloading the sites work immediately. 

They also work if the policy is in proxy mode because in proxy mode the FGT does no ASIC offloading.

 

TAC are still investigating this with us. Up to now their suggested workaround is to disable ASIC offloading. However Fortinet themselves do not recommend that because this will generate a higher CPU load on the FGT. 

 

Just wanted to post that in here for if anyone else runs into this.

-- 

"It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams

-- "It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams
14 REPLIES 14
BillH_FTNT

Hi sw2090

I 'd like to know the TAC number. We can make reproduce in our lab to check the issue. thanks

BillH_FTNT

Hi @sw2090 

In your case, could you reduce MTU in the client or server site? The client is better, MTU test can be 1340 ? Based on this information "website that use http v2 protocol will no longer work. They will load endless or/and timeout." It may be a packet loss or retransmission.

Regards

Bill

sw2090
Honored Contributor

Sent you the ticket number in pm.

Hm last time I went into this I did traffic captures on client and on FGT and I did not see any errors about missing packages etc. 

Testing is difficult here as normal clients are in productive use and in my own little lab it does work fine on a 60F.

-- 

"It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams

-- "It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams
BillH_FTNT
Staff
Staff

Hi @sw2090 

Can you share me the name of some "website that use http v2 protocol will no longer work. ". Thanks

Bill

BillH_FTNT

I tested our devices with full UTM, and they are all okay. So it can happen with some websites with big Server hello packets.

Regards/Bill

Labels
Top Kudoed Authors