Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Hakam
New Contributor III

Web Filtering- Slow page loading.

We are currently experiencing an issue with slow page loading when web filtering is enabled at the policy level. When web filtering is disabled, the page loading speed is normal. The issue occurs on all websites especially first time browsing any websites, with load times ranging from 5 to 20 seconds.

26 REPLIES 26
Hakam
New Contributor III

HI ap,
I already done with option 2.

Screenshot 2024-08-19 091421.png

 

When Proxy based apply, like all websites can't be access..

kumarh
Staff
Staff

Kindly check when issue occur is there any spike in CPU or Memory usage? Also, what is the inspection you are using in web-filter and in firewall policy? Try to change it and check number of session utm is using. You can refer below document : https://docs.fortinet.com/index.php/document/fortigate/6.2.5/cookbook/963365/checking-the-number-of-...

Hakam
New Contributor III

no CPU and memory spike. 

VinayHM
Staff
Staff

Hi 

Please check with flow-based mode on the policy.

 

Regards,

 

Vinay HM
Hakam
New Contributor III

Already check.. no issue.

sw2090
SuperUser
SuperUser

I also currently have slow internet and timout issues on some 100F that are on 7.2.9 (but also occured with 7.2.8) in my case it worked normal after I disabled asic offloading on the internet policy.

Since this can only be a workaround I've opened a ticket with TAC on this.

-- 

"It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams

-- "It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams
Hakam
New Contributor III

Hi @sw2090 ,

 

any link how to disabled asic offloading on the internet policy ?
I go to GUI, but not see the asic offloading.

sw2090
SuperUser
SuperUser

aslo there where several bugs with NPU in 7.2.8 and earlier that were fixed in 7.2.9. Though my issue is obviously not.

-- 

"It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams

-- "It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams
sw2090
SuperUser
SuperUser

unfortunately these options are not available on gui. You will have to add the column "ID" to the policy view  in gui to find the policy id and then set it on cli:

 

config firewall policy

 edit <id>

  set auto-asic-offload disable

end

 

Maybe you could also set np_acceleration to disable. But not sure if needed.

 

-- 

"It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams

-- "It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams
Hakam
New Contributor III

Hi @sw2090 ,

 

Thanks You for the suggestion, I will try later.

Btw, any root cause TAC has given for u issue?

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors