Traffic through fortigate firewall is extremely sluggish for some situations.
Depending on how a client gets out to the Internet, through the FG, is either very quick, or very sluggish.
client -> Linux proxy(port 3128) -> Fortigate(443) - Outside(443). Very quick
client -> Fortigate( Explicit Proxy port 3128) - Outside(443). Very quick
client -> Fortigate(443) - Outside(443). Extremely slow, and often times out.
The Linux proxy is in the same subnet as the client.(client is .4, proxy is .5) So it does not appear to be routing related. To the FortiGate the proxy should have the same path as the client. Hits the same rules, same routing...etc.
The client use the FG to resolve DNS and that does not seem to be affected. Reply come quickly.
The only main difference is that the client is Windows, and the proxy is Linux.
One of the clients and the FG are in Azure, but also have issues with a Windows 10 Vmware box coming in through a VPN. The VMs in Azure are different sizes, but the networking should be the same. Aside from the OS.
Basically, any client wanting to go out directly through the FG experiences slow 20+ second (or worse) load times for even the simplest sites. If a client uses either an Azure VM acting as a web proxy, or uses the FG as the web proxy, the responses are immediate. Have verified that the speediness is not related to caching on the proxy, and am pretty sure the FG does not do any. So the Azure proxy VM can access the Internet through the FG quickly, but any web client, whether inside Azure or from an external VPN, experience the slowness, and connections attempts often time out.. The odd thing to me, is that the web proxy in Azure has no slowness or time out issues when it goes through the FG on behalf of the client. But the same client going directly to the FG does. And it does not seem to matter where the client is located.
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.