[Internet]
      ^
      |
      |
      |    {problem segment}
      |          |
      |          |
      v          v
 [FGT1000a]<---------->[main switch]<-------->[inside network and clinics]
      ^
      |
      |
      |
      |
      |
      v
 [IPSec VPN sites via Internet]
 
 Here' s the problem.  The clinics that connect into my network from the FGT/Internet side are able to see each other with nice quick response times as well as browse the Internet the same way.  When they try to get back into my network, there is a very large delay.  i.e. clinic to clinic ping response time is 15-35ms, and Internet is 10-25ms.  Internal servers are 100-500ms!  Likewise from the inside, any one including the internal clinics that come in via T-1 pipes through a router inside the main switch can ping anything inside in <10ms.  Once they cross the point to point network to the Fortigate, times grow to between 100 and 350ms.  What' s gives?  Anyone?
 
 I have switched off auto configure on the main switch (Alcatel 7800) and forced 100MB/full there.  Is there a way to do this on the FGT1000a?  Also I have run a packet trace on that point to point segment and have seen nothing unusual.  Just a large amount of HTTP traffic.  Normal.
 
 Thanks all for your time.  Next step is a ticket with support.
					
				
			
			
				Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com
Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com
Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com
Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com
 
					
				
				
			
		
| User | Count | 
|---|---|
| 2678 | |
| 1412 | |
| 810 | |
| 704 | |
| 455 | 
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.