Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
pajass
New Contributor

Fortigate 90d 100% CPU on speedtest, only 250Mbps

Hi everyone, new here in the Forum :)

We have A Fortigate 90D.

When we measure the bandwith with speedtest.net from outside the firewall we get around 700Mbps.

Behind the firewall only 250Mbps and the cpu load goes to 100%. According to the datasheet it should theoretically support up to 3.5Gbps. No matter if Antivirus is activated or not.

I don't want to post the debug.log because of ip-adresses and so on, but I can provide further details if necessary.


Cheers Stephan

3 REPLIES 3
fiesta
New Contributor III

Dear Stephen,

What cause high CPU in diagnose sys top-summary or diagnose sys top.
If it's IPSmonitor, i think you should disable the Application Control and IPS if enabled. 

 

Regards.

FWD~
FWD~
amouawad
Staff
Staff

The FortiGate 90D supports 275Mbps for IPS/Application control traffic and 35Mbps for AntiVirus traffic (http://fortinet.globalgate.com.ar/pdfs/FortiGate/FortiGate-90D.pdf).

 

The 3.5Gbps is for firewall only traffic (no security profiles enabled), and only for UDP. TCP will be always be lower than this value but should definitely be higher than 250Mbps.

 

250Mbps is inline with this if your policy has Application Control/IPS turned on. Can you try disabling all security profiles on the policy and testing again?

ede_pfau
Esteemed Contributor III

Clearly, a throughput figure cannot be independent of applying AV or not.

 

Besides the 90D being an old model with a relatively weak embedded CPU, can it be the case that your WAN line is using PPPoE and the FGT is decoding it directly? In this case, CPU is the limiting factor. A simple modem in front will do PPPoE in hardware and will raise the throughput substantially.


Ede

"Kernel panic: Aiee, killing interrupt handler!"
Ede"Kernel panic: Aiee, killing interrupt handler!"
Labels
Top Kudoed Authors