Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
AlexImpact
New Contributor

Slow video streaming

Hi, I need your help, I have 2 fortinet 200b in HA and a 100Mb Internet connection. But watching videos online often lag really bad, stopping every time to buffer, watching a 10 minutes video is like 30 minutes of buffering, watching the same video from the same source on a much slower connection like at home is no problems at all. Can anyone help? most documents I found online are to restrict video streaming, nothing on how to speed it up. But the business I work for need to be able to reliably watch these videos. Thanks
14 REPLIES 14
rwpatterson
Valued Contributor III

Welcome to the forums. A quick test: Turn one of the HA units off. I found in v4.2.13 (I think) that having the units in A-A slowed down throughput. I never put a ticket in, just switched to A-P mode instead.

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
Dave_Hall
Honored Contributor

Hi Alex. Welcome to the forums. Use the search link (above) and look for youtube slow/stalled connection issues. You did not indicate which firmware the 200Bs are running. But on 4.0 MR3 (and may be earlier) firmware, slow or stalled video streaming may be related to how the fgt buffers incoming " files" (if the fgt is in proxy mode) and/or if disk caching is enabled (don' t have fgt in HA so don' t know if disk caching is even allowed in HA). In 4.0 MR3 you will want to look at Protocol Options (under Policy->Policy->Protocol Options), in 5.0 I think the file size option is controlled by DLP. Edit: sort of an after thought, in additional to what Bob pointed out and what I wrote (above)...guess we are all assuming there is nothing wrong with the WAN connection, but you should rule that out as being part of the problem (e.g. MTU, duplex/speed mismatch, etc.).

NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C

NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C
AlexImpact
New Contributor

I' m running 4.0 MR3 in Actives-Actives mode I may try to change to Actives-Passives to see if it help, Can I do this change live without affecting users? I also add the URL of the website from witch we want to stream into the exempt list of the cache Under Policy/Policy/Protocols Options, under HTTP I have Oversised File/EMail to Pass and threshold I changed to 1 to test (was 10)
rwpatterson
Valued Contributor III

Switching modes will have negligible affect on the users. Some tunnels may drop, but that is only a maybe.

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
AlexImpact
New Contributor

Changing from A-A to A-P had no effect, I must add, that it' s not video from youtubes that are problematics, it' s video from instatscout.com, which use JW Player to stream video. so far nothing did help
Maik
New Contributor II

Do you use " comfort clients" in your protocol options? what values?
Dave_Hall
Honored Contributor

I must add, that it' s not video from youtubes that are problematics, it' s video from instatscout.com, which use JW Player to stream video. so far nothing did help
If it is just one site and one that is " critical" to your company and is a trusted site, you can try creating a separate fw policy for that site only with no UTM features enabled...just as a test, to help in troubleshooting this problem. (Create a fqdn for instatscout.com and use that for the dest address.) Move the fw policy up in the fw chain so it is triggered.

NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C

NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C
donnat
New Contributor III

Hi, For me: config webfilter content-header edit 1 config entries edit " video/.*" set action exempt next edit " audio/.*" set action exempt next end set name " Liste-content-header" next end

Cluster Active/Passive Fortigate-1500D 6.0.9 (AV, DLP, AppCtrl & IPS, DHCP, AlertMail, Fortiguard Web & AS, OSPF & RIPv2, SSL-VPN Portal Web and Tunnel) FortiAnalyzer-3000D 6.0.8 (Log, Syslog, Alert event, Quarantine & Report)

Cluster Active/Passive Fortigate-1500D 6.0.9 (AV, DLP, AppCtrl & IPS, DHCP, AlertMail, Fortiguard Web & AS, OSPF & RIPv2, SSL-VPN Portal Web and Tunnel) FortiAnalyzer-3000D 6.0.8 (Log, Syslog, Alert event, Quarantine & Report)
AlexImpact
New Contributor

I tried donnat suggestion, didn' t help, tried to create a separate fw policy as dave suggest, still no help, I' m starting to think it may be something with my inet provider, To answer Maik question, I dont use comfort clients, should I? If I was to set comfort client, should I do it under HTTP for video? This website is somewat critical for our business, we are a professionnal soccer team and scouting agents use this to scout new prospect players. Thanks everyone for trying to help me, if you have any others suggestion for me to try, please go ahead.
Labels
Top Kudoed Authors