I noticed when I do a speed test my upload speed is always greater than my download. I'm new to FortiGate pls help me with a solution.
Solved! Go to Solution.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
If you're load-balancing between two circuits and run a speed test with a server on the internet, likely it's testing only one side since the source&destination is a same set of IPs. But besides that I would run speed test by shutting down one ISP circuit to get a consistent measurable outcome.
Anyway, I have to assume like one ISP circuit is 80Mbps down/20Mbps up, and you get 0.1K-2Mbps down/16Mbps up in the speed test. Then most likely a duplex-mismatch is happening on the path between ISP circuit and your machine running the test.
There are many discussion in this forum about this subject. Search discussions with "duplex mismatch", and you can find the mechanism how it happens and how to find where the point(s) is(are). On the FGT side, to find how it's operating is "diag hardware deviceinfo nic <interface_name>". You always need to check on the other side as well.
You need to provide more information to get any comments, like what's the circuit speed, is that larger than circuit speed, is download speed lower than it should be, how much greater, and so on.
toshiesumi wrote:We are using Two ISP's with a total combined bandwidth of 160Mbps. The download speed I get between 0.1kbps to a maximum of 2mbps while the upload speed is going up to 16mbps. Pls what might be the problem.You need to provide more information to get any comments, like what's the circuit speed, is that larger than circuit speed, is download speed lower than it should be, how much greater, and so on.
If you're load-balancing between two circuits and run a speed test with a server on the internet, likely it's testing only one side since the source&destination is a same set of IPs. But besides that I would run speed test by shutting down one ISP circuit to get a consistent measurable outcome.
Anyway, I have to assume like one ISP circuit is 80Mbps down/20Mbps up, and you get 0.1K-2Mbps down/16Mbps up in the speed test. Then most likely a duplex-mismatch is happening on the path between ISP circuit and your machine running the test.
There are many discussion in this forum about this subject. Search discussions with "duplex mismatch", and you can find the mechanism how it happens and how to find where the point(s) is(are). On the FGT side, to find how it's operating is "diag hardware deviceinfo nic <interface_name>". You always need to check on the other side as well.
toshiesumi wrote:Thanks for the info. I will check it and update you.If you're load-balancing between two circuits and run a speed test with a server on the internet, likely it's testing only one side since the source&destination is a same set of IPs. But besides that I would run speed test by shutting down one ISP circuit to get a consistent measurable outcome.
Anyway, I have to assume like one ISP circuit is 80Mbps down/20Mbps up, and you get 0.1K-2Mbps down/16Mbps up in the speed test. Then most likely a duplex-mismatch is happening on the path between ISP circuit and your machine running the test.
There are many discussion in this forum about this subject. Search discussions with "duplex mismatch", and you can find the mechanism how it happens and how to find where the point(s) is(are). On the FGT side, to find how it's operating is "diag hardware deviceinfo nic <interface_name>". You always need to check on the other side as well.
Also, try a speed test from two different units. The NIC settings may be off on one of them. Buffers, packet max sizes, etc.
Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com
Shame, the output did not include the speed/duplex info. However, what stands out is the RX errors:
From an old post, it seems to be hardware accelerator related, so you could try disabling "checksum offloading". Anyone else care to chime in on this.
NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1690 | |
1087 | |
752 | |
446 | |
228 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.