Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
AdrianOlson
New Contributor

Software Switch performance

I have a FWF-60D that i have created a software switch to bridge the Internal and WIFI networks into a single network. I also have a DMZ network, but when I do a file transfer to the DMZ network from the internal, I only get about 23MB/s. While transferring I also see the CPU usage @ 100%. Is this a by product of the software switch? my knowledge leads me to believe in this scenario I am CPU limited and not hardware limited (GbE). Am I on the right track? Are there any other ways to achieve this?
FWF-60D - 5.0.6 FWF-30D - 5.0.6 FGT-100D - 5.0.6
FWF-60D - 5.0.6 FWF-30D - 5.0.6 FGT-100D - 5.0.6
1 Solution
ede_pfau
SuperUser
SuperUser

hi, and welcome to the forums (though a little late). You' re absolutely right. Software switch (as opposed to hardware switch) means just that - the CPU handles all packets. Especially the Fortigates with SoC (system on chip) offer relatively weak CPUs, 20C/40C/60C and the D series. In a 80C the effect is way less noticeable. Look here for a list of Fortigate models and their hardware: https://forum.fortinet.com/FindPost/100451 Only in some of the latest midrange FGTs and using FOS v5 you can create a hardware switch. For a workaround consider just routing the WiFi subnet.

Ede Kernel panic: Aiee, killing interrupt handler!

View solution in original post

Ede Kernel panic: Aiee, killing interrupt handler!
13 REPLIES 13
rwpatterson
Valued Contributor III

Not quite your answer, but I have the WiFi (wlan), wan2, Internal2, Internal4 and Internal6 built into a switch in NAT/Route mode on a FWF80CM without issue. The DHCP is forwarded to a Windows box, and both wired and wireless share the same IP address space happily. Hope that does something for your testing. Here' s an idea for you:
  • Create a second VDOM in NAT/Route mode
  • Create a VLAN, same number on both
  • Pass the VLAN traffic across the inter VDOM links
  • Bridge the VLAN and internal on one, and the VLAN and WiFi on the other.
  • Bob - self proclaimed posting junkie!
    See my Fortigate related scripts at: http://fortigate.camerabob.com

    Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
    ede_pfau
    SuperUser
    SuperUser

    No doubt it works, the original question was about the performance hit. As I said, the 80C still is a work horse with a decent CPU. Not comparable to the 60D, 90D, 100D which boast high throughput for accelerated traffic but falter with SSL traffic and soft switching. With a newer model, it would be best to pick a model with hardware switch support.
    Ede Kernel panic: Aiee, killing interrupt handler!
    Ede Kernel panic: Aiee, killing interrupt handler!
    ShrewLWD
    Contributor

    Old thread, but still an issue for us... 5.2 does not solve the issue of a wifi, in a transparent VDOM, not broadcasting its SSID.
    nothingel
    New Contributor III

    I' m also interested in trying this transparent vdom idea. Have you tried reversing the process where the wifi is in the root vdom? I find that wifi always taxes the CPU even without bridging. Is this everyone else' s experience? I' m talking about a FWF-60C here. I also cannot obtain speeds faster than about 20Mbit/s over wifi. This is fairly good for " g" speeds but I also see this for " N" speeds on either 2.4 or 5ghz (the clients show 130 or 270mbps connection rates).
    Announcements
    Check out our Community Chatter Blog! Click here to get involved
    Labels
    Top Kudoed Authors