- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
WAN bandwidth peaks of 1.5Gbps
Hi all,
We are seeing some strange peaks in our WAN bandwidth. Every 20 minutes, we get a peak of around 1.5Gbps which lasts for about 1 minute. We can not figure out what is doing this.
We did a packet capture when the peak is going, but when looking in wireguard -> statistics -> conversations, we can only see 5 things that are around 15Mbps. To IP addresses that are not being used in any VIP.
How can we further troubleshoot this?
Edit: We've also checked all firewall rules comming into the fortigate, but none of them are producing this many Gbps..
- Labels:
-
FortiGate
-
WAN optimization
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi Jesper
Try enable logs for the implicit deny rule and check again. Probably the peaks are for incoming packets that are being blocked.
Also check in the local traffic logs as well.
Created on ‎03-04-2025 06:47 AM Edited on ‎03-04-2025 06:47 AM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I've enabled the implicit deny rule logging now, I have to wait for the next peak.
If it is this, how can we prevent it from peaking to 1.5Gbps, because of this we are paying around 300 euro's monthly to burst fees as we only have 100Mbps bandwidth..
Local traffic log is empty..?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Lets see in the logs then we can decide what to do.
But if it is blocked traffic from a source that is not controlled by you, then you can't do anything about that. You can just continue to block it and pay for it.
Local traffic log should not be empty. Try enable it in log settings.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Currently, all of the logs in forward traffic are 0 Bytes
I also found this inside the implicit deny firewall policy. the total bytes shouldn't be this low if every 20 minutes 1.5Gbps comes in right?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I think you are right.
Can you check the graphs of all other interfaces? In case you find an interface having the same peak at the same moment that would mean you have found at least to which local network this traffic is going.
