HI THERE ,i have really big problem , im doing Outbound SSL decryption with deep packet inspection on my fortigate , i have 10G connection , but when i use deep packet inspection my download speed limits to 200kbs or something near that, my upload is just work fine , and when ever i put SSL Profile to no inspection it gets fixed . i dont have any overhead on my device. what the problem could be ? Thanks in advanced.
Solved! Go to Solution.
And what is your policy mode? Is it in proxy or flow?
Is it the same in both situations? (should be proxy-)
It seems that you are using a SoC unit (low-end series/smaller units, up to 200 Series) that lacks the processing power or dedicated CPU (CP8/CP9) for SSL decryption. There might be limitations to the bandwidth used, so that the processor (that handles all the operations) does not reach top usage with only one connection
hi there, im using 200f, and i think it has dedicated cpu for decryption
in that case you probably need to check the traffic in a packet capture, looking for retransmissions, errors, etc. And if you still don't see any, then opening a support case may be the way to go.
Thank you for putting time and helping me . acctually after packet capture i have lot of retransmission, duplicated packet, and sometime out of order, but mostly retransmissions , so the slow speed is cuz of that ? , what i can do in order to fix this ? thanks
here is glance of wireshark cap
Not everything there is necessarily an error. If the traffic is passing multiple interfaces, the packet analyzer interprets them as errors. Try to redo the capture only on the wan interface.
Most common cause for packet retransmissions is network congestion. So the link quality should be checked (start with local cables, connectors, ISP router if exists).
The traffic is going out from one interface , to our core router, i dont think there is anything faulty such as cable or conncetors,because when i turn off the ips profile , it get fixed . no any spurious retranssmiton or anyother of the logs thati have shown , and prefect speed, i even tried the IPS profile only with 1 signutaure and still same result
And what is your policy mode? Is it in proxy or flow?
Is it the same in both situations? (should be proxy-)
btw my cpu process is under 5 %
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1737 | |
1108 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.