Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
rwpatterson
Valued Contributor III

UTM throttling Internet speed

OK, I have a symmetrical 100 Mbps Internet pipe. When I browse to speedtest.net with UTM turned off, I get 78-89 Mbps all day. The minute I enable UTM (even without checking ANYTHING else) the download speed immediately drops to less than 1 Mbps. Sick! The new CIO is a Cisco guy, so I' m not sure I' ll be on here posting much longer, even if I get this figured out in the next couple of days. Any hints folks? Thanks in advance. Bob P.S. - Don' t bother trying to talk to me about what to tell him, he' s not listening. A deaf ear to reason, full speed ahead with the other.....stuff...

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
17 REPLIES 17
billp
Contributor

Bob, Just a wild guess. . . Have you gone through the config file to see if there are any oddball settings hiding somewhere? It sounds like something, somewhere is definitely turned on.

Bill ========== Fortigate 600C 5.0.12, 111C 5.0.2 Logstash 1.4.1

Bill ========== Fortigate 600C 5.0.12, 111C 5.0.2 Logstash 1.4.1
Matthijs
New Contributor II

What unit do you have? Have you checked the cpu usage of the box when running speedtest? By finding out what process is busy during the speedtest you might find what scanning is done.
ede_pfau
SuperUser
SuperUser

We definitely cannot afford to lose you here on the Forums - we gotta find out what' s going on. I assume it' s the 1000A running 4.2.15. What would I do? I' d take a different but capable hardware (like the 80C), put 4.2.15 on it and re-test. If that succeeds then the 1000A build has got a bug. I' d try a different firmware version like 4.2.12 and 4.3.12 to get a feeling if it' s version dependent. I see it' s an active-active cluster. That means AV load sharing to an extent. This will make troubleshooting a bit more complicated. Have you filed a Support case yet? If you like I may check the config file (pm) but I don' t think you didn' t do that already. I suspect it' s either a bug or a HA side effect.
Ede Kernel panic: Aiee, killing interrupt handler!
Ede Kernel panic: Aiee, killing interrupt handler!
rwpatterson
Valued Contributor III

Thanks for the positive responses... Needed after a crazy day out in the trenches. I' ll try some of these as soon as time permits. 1000A A-A, under 30% CPU during the tests. No IPS at all. Will give you more when I get more.

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
Dave_Hall
Honored Contributor

UTM covers a lot of things -- including a lot of gotchas, such as " hidden" packet logging or traffic shaping, various protocol options set to auto scan, etc. I assume you created separate firewall policies tailored for different traffic (http/https, POP3/SMTP/NTP/DNS, etc.) and enabling only those UTM features for that type of traffic.

NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C

NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C
harald21
Contributor

Hello, have you opened a ticket yet? I know Fortinet technical support has a monitoring script for finding bottlenecks. Sincerely Harald
emnoc
Esteemed Contributor III

Give us an example or what you mean " enable UTM" , but haven' t checked anything?

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
rwpatterson
Valued Contributor III

ORIGINAL: emnoc Give us an example or what you mean " enable UTM" , but haven' t checked anything?

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
Matthijs
New Contributor II

Have you tried enabling one of the features (a light one like mail filtering) to see if this helps? Maybe the FortiGate enabled a random feature when nothing is checked :p
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors