Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Eric72
New Contributor II

Very high latency between lan and dmz on VM64 (multiple vdoms, multiple emac vlans)

Hi!  We have a pair of Fortigate VM64 in HA on VMware (provider is OVH).

We are migrating clients from PaloAlto to this Fortigate.

 

We have around 30 VDOM (and we need to add more), with VDL link to the root.

We have EMAC VLANS for the interface (WAN, Private and DMZ).

 

It is working, but when the sessions increase around 30K and higher, everything become very slow.

The ping between private and dmz inside any vdom increase around 100-150ms with lost packets.

 

The CPU is used max 20%, and the memory around 60%.

 

We have a ticket with Fortinet, but for them , with a packet capture, there were able to show that the fortigate don't add any latency in the packets.

 

We move back one of the client to PaloAlto and they are now happy!

The PaloAlto use the same VMware farm.

 

To be able to make the EMAC VLAN and VDL work, we needed to enable the promicious mode on the port group on VMware. Maybe this is the problem.

 

The links are 10GBs, and the traffic on the trunk that contains the private and dmz don't even go higher than 2.5Gbs.

 

If someone has an idea what could be the problem...  

 

thank you

 

 

 

1 Solution
Eric72
New Contributor II

We found that the problems came from not enough resources. Too much cpu ready.

We move the firewall alone on a vsphere host and there's no more problem.

 

View solution in original post

4 REPLIES 4
Anthony_E
Community Manager
Community Manager

Hello Eric,


Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.


Thanks,

Anthony-Fortinet Community Team.
Jean-Philippe_P
Moderator
Moderator

Hello,

 

We are still looking for an answer to your question.

 

We will come back to you ASAP.

 

Thanks,

Jean-Philippe - Fortinet Community Team
Eric72
New Contributor II

We found that the problems came from not enough resources. Too much cpu ready.

We move the firewall alone on a vsphere host and there's no more problem.

 

Jean-Philippe_P
Moderator
Moderator

Hello again Eric72!

 

Thanks for sharing the solution with everybody and glad that you fix your issue :)

Do not hesitate to contact us if you have furthers issues

Jean-Philippe - Fortinet Community Team
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors