Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
rwpatterson
Valued Contributor III

Network congestion

I have my nework configured as in the following diagram:
 [Internet]
      ^
      |
      |
      |    {problem segment}
      |          |
      |          |
      v          v
 [FGT1000a]<---------->[main switch]<-------->[inside network and clinics]
      ^
      |
      |
      |
      |
      |
      v
 [IPSec VPN sites via Internet]
Here' s the problem. The clinics that connect into my network from the FGT/Internet side are able to see each other with nice quick response times as well as browse the Internet the same way. When they try to get back into my network, there is a very large delay. i.e. clinic to clinic ping response time is 15-35ms, and Internet is 10-25ms. Internal servers are 100-500ms! Likewise from the inside, any one including the internal clinics that come in via T-1 pipes through a router inside the main switch can ping anything inside in <10ms. Once they cross the point to point network to the Fortigate, times grow to between 100 and 350ms. What' s gives? Anyone? I have switched off auto configure on the main switch (Alcatel 7800) and forced 100MB/full there. Is there a way to do this on the FGT1000a? Also I have run a packet trace on that point to point segment and have seen nothing unusual. Just a large amount of HTTP traffic. Normal. Thanks all for your time. Next step is a ticket with support.

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
7 REPLIES 7
jasonb_FTNT
Staff
Staff

What' s the bandwidth usage on the T-1s ?
rwpatterson
Valued Contributor III

The T-1s that terminate on the inside have 5 facilities attached. They are subscribed at 4x256k, and 1 at the full T. The three facilities attached to the 1000a are cable connected at 5MB down/500KB up. Logging into Novell (yeah we use it) takes about three minutes over the cable connection, but about 20-30 seconds over the Ts.

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
jasonb_FTNT
Staff
Staff

What build are you running? Do you know how to use dia debug flow? LAB_FGT50B # dia debug flow filter addr 1.1.1.1 1.1.1.1 LAB_FGT50B # dia debug flow show console enable show trace messages on console LAB_FGT50B # dia debug flow trace start 999 Configure an filter for the IP of the Novell server. Try to login remotely the same way as remote users would. To stop the trace dia debug flow trace stop to see what filters you have dia debug flow filter To remove the filters : dia debug flow filter clear Sounds like a routing issue, are these interface based VPNs? If you traceroute from remote end does the traceroute go over the paths you expect?
rwpatterson
Valued Contributor III

The build is in my signature. These are all interface based VPNs running OSPF. Only the 1000a has static routes that it is redistributing. Checked the routing several times. The traceroute does follow the expected path. I' ll try the suggestions you posted as well. Thanks for the help!

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
rwpatterson
Valued Contributor III

Upgraded the firmware to build 568, and the problem disappeared. Who would have thought? Thanks all for your suggestions. Especially Jason. A mod that know his stuff. Welcome change! Spoke too soon. After the usage grew, so did the delays.... Hopefully the final solution. I had originally turned our main switch (Alcatel) to 100/full on the port. This started off with fast response times, but later did nothing as network traffic increased. I then switched (from the console) the Fortigate to 100/full to match, and rebooted. All communication between the devices was lost. I switched the Alcatel to auto/auto, and now in peak Internet time after about 15 minutes, speeds are screaming fast. I' m a happy individual once again. If things change, you' ll all be the first to know.

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
jasonb_FTNT
Staff
Staff

Also get the output of the following command on the problematic segment :- dia hardware deviceinfo nic <port>
jasonb_FTNT
Staff
Staff

You can set the interface speed with the following command :- # conf system interface (interface) # edit wan2 (wan2) # set speed ?
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors