Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
jrusso
New Contributor

WAN performance

We own a FG-60C. Our company recently got a new 20/20 Mbps DSL line, however when we do a speed test (speedtest.net, speakeasy.net) behind the firewall we only get around 2-3 Mbps when downloading and around 20 Mbps when uploading. When we connect a pc straight to the DSL router, we get close to what the actual speeds ought to be. UTM is turned off, so no web-filter, AV, IPS, etc. What I' d like to know is how do you troubleshoot this issue. I see the traffic log, but it' s not telling me much. Anyone know how to begin tackling such an issue? -Thank you in advance
12 REPLIES 12
rwpatterson
Valued Contributor III

Welcome to the forums. Here' s a question: When you use the Fortigate inline, how many people are sharing the connection?

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
jrusso
New Contributor

Thank you, rwpatterson. Around 45 people in the office, however even if there' s only one user online, the speed is the same (I stayed in the office after hours testing). I should also note that Fortigate is running v4.0 MR1 OS. Also, the ISP tech said the at line is setup as full duplex which is what the WAN port is also set as. We have a backup unit that I plan to use for testing so as not to disrupt our users. I' m going to upgrade that unit to the latest firmware and see if it makes a difference.
rwpatterson
Valued Contributor III

Try the latest version in V4 MR2 (patch 14) before going to V4 MR3 (my opinion) and DEFINITELY before going to V5 (general consensus).

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
jrusso
New Contributor

Thanks for the tip!
Dave_Hall
Honored Contributor

Before upgrading from 4.0MR1 to 4.0MR2 make sure there are no space character codes in the address/firewall object labels -- we ran into problems while upgrading from 4.0MR1 to 4.0MR2 -- most of our firewall polices broke (on the units we upgraded) and we spent a few hours tracing the problem to our addressing labels getting truncated at the first space char in the name, after the upgrade. Still having problems after the upgrade, run a " diag hardware deviceinfo nic <wan port>" test and check for any errors on the port (ie. possible duplex/speed mismatch).

NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C

NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C
jrusso
New Contributor

Thanks for the tip, Dave. Did the upgrade on the spare unit to MR2, plugged it in and still no dice. Speed tests still show 2-3 Mbps. Also ran the diagnostic command as suggested and it showed no errors. The port is correctly figure as 100mbps full duplex. I should mention that I copied the config file from the active unit into the spare. I' m thinking of resetting the spare and just start from scratch.
rwpatterson
Valued Contributor III

As a suggestion, from the GUI, drop the MTU to a lower number...say 1490. If packets need to be fragmented, that may slow you down as well. If you want to see what the largest packet the interface will bear, from a DOS prompt, type:
 C:\ ping 8.8.8.8 -f -l <packet size>
The largest packet you' ll be able to squeeze will probably be 1500. If that doesn' t work, try decreasing this number by about 10 until it works, then either take that or increase gradually until it fails. This is the number you need to enter in the GUI on the interface.

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
Coldfirex
New Contributor

From my experience speedtest sites will always give you funky results behind a UTM. Are you sure UTM is completely off for the traffic getting to the website? I would test out real downloads/uploads to test the performance.
ede_pfau
SuperUser
SuperUser

The reason for this asymmetric throttling most probably is in the config (which you unfortunately copied from the live unit). From the console port prompt, do a " exec factoryreset" , put in an IP address for ' internal' , configure the WAN port and add just one policy allowing traffic out. Nothing else. Then measure. Speedtest is suitable enough for such a gross mismatch.

Ede

"Kernel panic: Aiee, killing interrupt handler!"
Ede"Kernel panic: Aiee, killing interrupt handler!"
Labels
Top Kudoed Authors