- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Load test packet loss
I am try to load test FortiGate VM using cisco Trex. While this works perfectly on the current pfsense setup, I cannot get it to work on FortiGate.
Simple routing and firewall rules have been set up the same as pfsense and can see that the one firewall rule is beng used based on the bandwidth usage. When looking at foward traffic logs it seems that some traffic is getting through fine but the majority of traffic does not seem to be accepted as is mostly droppped.
I have tried the following so far;
- Using Policy routes rather than static routes produces the same result
- Change the interface types from unspesified to WAN or LAN
- Added DoS policy, no change
- Changed NAT settings in firewall rules
- Changed protocol options in firewall rules
Looking at forward traffic it seems that traffic that is having issues is the following
Duration | 5 |
Session ID | 63,877 |
VDOM | root |
NAT Translation | noop |
Source | 16.0.0.14 |
Source Port | 5,796 |
Source Country/Region | United States |
Primary Source Mac | 00:0c:29:93:42:f3 |
Source Interface |
port1 |
Destination | 48.0.7.7 |
Destination Port | 80 |
Destination Country/Region | United States |
Destination Interface |
port2 |
Application Name | HTTP |
Category | unscanned |
Protocol | 6 |
Service | HTTP |
Received Bytes | 33.02 kB |
Received Packets | 23 |
Sent Bytes | 813 B |
Sent Packets | 14 |
Action | client-rst |
Security Action | |
Policy ID | 0to1 |
Policy UUID | 57417294-aca1-51ed-d32e-e59d083a0abd |
Policy Type | Firewall |
Level | notice |
Service | HTTP |
Log event original timestamp | 1676410894150044700 |
Timezone | +0000 |
Log ID | 0000000013 |
Type | traffic |
Sub Type | forward |
Source Interface Role | wan |
Destination Interface Role | lan |
Policy Name | 0to1 |
Source Server | 0 |
- Labels:
-
FortiGate
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
You probably should have deployed FortiGate-VM64.hw13.ovf to match your version of ESXi. Did you do that?
Graham
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Funniley enough i did choose the wrong package when i first tried to install but ESXi gave a load of errors. Went back and check the documentation and used the correct package, installedyet fine. I even went back to the old versions and tried using the FortiGate-VM64.hw13.ovf and the result was the same. Works for 10 seconds then majority packet loss
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
What version of FortiOS are you running?
Graham
Created on ‎03-01-2023 01:37 PM Edited on ‎03-01-2023 01:38 PM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Currently have v 7.2.4 build1396 installed and have also tried on v7.0.3 build237
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
What version of FortiOS?
Graham
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
So what hardware version is your VM using?
Graham
Created on ‎03-03-2023 04:41 AM Edited on ‎03-03-2023 04:44 AM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Have tried on VMXNET3,e1000 and e1000e. Same result on all of them sadly. After reviwing the pfsense logs, my best guess at the moment is some sort of security service or setting on Fortigate somewhere that is causing this behaviour.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
No i mean what VMWARE hardware version is your Guest VM configured to use? You need to ensure you are using the compatible hardware version for your hypervisor and that you are running the correct FortiGate VM image for that hardware version.
Graham
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Sorry for the late reply/
Other 3.x or later Linux (64-bit)
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
No not asking what Guest OS version you are using. What VMware Hardware Version your Guest VM is set to.
https://kb.vmware.com/s/article/1003746
Being on ESX 6.5 you need to be at least version 13 which means you need to deploy the right FortiGate-VM ovf for that hardware version. But please confirm what you are actually using.
Also please let us know what NIC you have in your server?
Also please run through the instructions for optimizing VM performance and best practices:
Graham
