Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
rwpatterson
Valued Contributor III

UTM throttling Internet speed

OK, I have a symmetrical 100 Mbps Internet pipe. When I browse to speedtest.net with UTM turned off, I get 78-89 Mbps all day. The minute I enable UTM (even without checking ANYTHING else) the download speed immediately drops to less than 1 Mbps. Sick! The new CIO is a Cisco guy, so I' m not sure I' ll be on here posting much longer, even if I get this figured out in the next couple of days. Any hints folks? Thanks in advance. Bob P.S. - Don' t bother trying to talk to me about what to tell him, he' s not listening. A deaf ear to reason, full speed ahead with the other.....stuff...

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
17 REPLIES 17
Dave_Hall
Honored Contributor

Based on Bob' s screen-shot, it looks like he enabled UTM on an identity based policy. Searching through past posts on these forums, the closest post(s) related to Bob' s issues is this thread. In that thread it seems the problem is related to a routing issue with the fgt contacting the FortiGuard servers. However, Bob hasn' t enabled any actual UTM features yet.

NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C

NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C
rwpatterson
Valued Contributor III

ORIGINAL: Dave Hall Based on Bob' s screen-shot, it looks like he enabled UTM on an identity based policy. Searching through past posts on these forums, the closest post(s) related to Bob' s issues is this thread. In that thread it seems the problem is related to a routing issue with the fgt contacting the FortiGuard servers. However, Bob hasn' t enabled any actual UTM features yet.
+1 for bringing this old post to light.

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
ede_pfau
SuperUser
SuperUser

What I' ve read between the lines in the cited thread from 2011 is that WF plus a standalone FGT works OK but WF plus an HA pair is slow. That would be worthwhile to test. Unfortunately, I don' t have access to a pair of FGTs for testing myself. Support should be able to do it though.
Ede Kernel panic: Aiee, killing interrupt handler!
Ede Kernel panic: Aiee, killing interrupt handler!
rwpatterson
Valued Contributor III

It' s quiet here today. I' ll power down one of the units and give it a shot. Thx for working with me guys. Bob

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
rwpatterson
Valued Contributor III

ORIGINAL: ede_pfau What I' ve read between the lines in the cited thread from 2011 is that WF plus a standalone FGT works OK but WF plus an HA pair is slow. That would be worthwhile to test. Unfortunately, I don' t have access to a pair of FGTs for testing myself. Support should be able to do it though.
Had to be in at 2:00 AM local time for another issue. I yanked the power on the second 1000A, and it seems that the speed is back to what is expected (dammit!). I' ll leave it like so for a couple of days to see what the deal is here... Good call Ede! +2 for you!

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
discoveryit
New Contributor

One thing i would check is to make sure, if you have a switch between you and the internet source make sure it is set to the correct Duplex. We had a similar issue before and the duplex was set to Half on the ISP Cisco Router and the switch was at full. Also if you enable the Protocol Settings and configure the Comfort Client does it change anything?
FCNSP
FCNSP
rwpatterson
Valued Contributor III

Duplex is fine. The biggest speed drops are only when UTM is turned off/on. After it' s been enabled, nothing else checked behind it slows it down any more. No chance this weekend to test. No news as of yet folks. Stay tuned.

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
ede_pfau
SuperUser
SuperUser

Cool! So that would be a bug, and enough for Support to look at it. Really incredible, at patch 15...
Ede Kernel panic: Aiee, killing interrupt handler!
Ede Kernel panic: Aiee, killing interrupt handler!
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors