- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Outbound-Decryption
HI THERE ,i have really big problem , im doing Outbound SSL decryption with deep packet inspection on my fortigate , i have 10G connection , but when i use deep packet inspection my download speed limits to 200kbs or something near that, my upload is just work fine , and when ever i put SSL Profile to no inspection it gets fixed . i dont have any overhead on my device. what the problem could be ? Thanks in advanced.
Solved! Go to Solution.
- Labels:
-
Customer Service
-
FortiBridge
-
FortiGate
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
And what is your policy mode? Is it in proxy or flow?
Is it the same in both situations? (should be proxy-)
- Toss a 'Like' to your fixxer, oh Valley of Plenty! and chose the solution, too00oo -
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
It seems that you are using a SoC unit (low-end series/smaller units, up to 200 Series) that lacks the processing power or dedicated CPU (CP8/CP9) for SSL decryption. There might be limitations to the bandwidth used, so that the processor (that handles all the operations) does not reach top usage with only one connection
- Toss a 'Like' to your fixxer, oh Valley of Plenty! and chose the solution, too00oo -
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
hi there, im using 200f, and i think it has dedicated cpu for decryption
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
in that case you probably need to check the traffic in a packet capture, looking for retransmissions, errors, etc. And if you still don't see any, then opening a support case may be the way to go.
- Toss a 'Like' to your fixxer, oh Valley of Plenty! and chose the solution, too00oo -
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thank you for putting time and helping me . acctually after packet capture i have lot of retransmission, duplicated packet, and sometime out of order, but mostly retransmissions , so the slow speed is cuz of that ? , what i can do in order to fix this ? thanks
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
 here is glance of wireshark cap
 
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Not everything there is necessarily an error. If the traffic is passing multiple interfaces, the packet analyzer interprets them as errors. Try to redo the capture only on the wan interface.
Most common cause for packet retransmissions is network congestion. So the link quality should be checked (start with local cables, connectors, ISP router if exists).
- Toss a 'Like' to your fixxer, oh Valley of Plenty! and chose the solution, too00oo -
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
The traffic is going out from one interface , to our core router, i dont think there is anything faulty such as cable or conncetors,because when i turn off the ips profile , it get fixed . no any spurious retranssmiton or anyother of the logs thati have shown , and prefect speed, i even tried the IPS profile only with 1 signutaure and still same result
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
And what is your policy mode? Is it in proxy or flow?
Is it the same in both situations? (should be proxy-)
- Toss a 'Like' to your fixxer, oh Valley of Plenty! and chose the solution, too00oo -
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
btw my cpu process is under 5 %
