Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
rpozywak
New Contributor

Network Slowness 60D-POE

At a remote site I have a 100mb Internet connection coming into a Fortinet 60D-POE Firewall. The users were complaining about slowness to the Internet. If I plug directly into the Cisco 3750 switch and run a speed test I get 30mb x 10mb. If I plug directly into the firewall and do the speed test again I get 112mb x 10mb. Thinking is was a bad switch I just got a layer two switch and plugged the firewall directly into that switch, along with my laptop. I reran the speed test and got the same result 30mb x 10mb. Thinking it might a link speed issue from the firewall to the switch. I installed a 1000gb module on the Cisco switch and made sure the firewall and the switch was set to 1000gb and full duplex and I still get the slower speeds. I checked the switch interface and there are no errors or collisions. At this point I am lost what is causing this problem. Any insight to this would be appreciated. Thanks, Richard
6 REPLIES 6
mhekscrip
New Contributor

Is there any policy you created at traffic shaper to interface where the switch is connected? Maybe try to check your policy first.

Srujan

Hi

 

login to the firewall from putty and check if the port inbound and outbound speed are limited to some values

 

#config system interface

#edit wan1

#get

 

In the result check for

inbandwidth         : outbandwidth        :

 

Thanks

srujanm

Toshi_Esumi
Esteemed Contributor III

One thing that alarms me is you wrote "...set to 1000gb and full duplex" on both FW and SW. How about the port on the SW you hooked up your laptop? I'm assuming your laptop is set to auto/auto. If you hook up at a port the speed/duplex was hard-set, it might end up with 1000G/half-duplex.

rpozywak

Hello everyone.    I have checked my policies and I currently have no policies applied.    I rand the command for WAN #1 and this what was listed and I have nothing showing in or out bandwidth.  On the switch where the laptop is plugged in at that port is set to auto / auto the same with the laptop.  I hope this helps..   I placed a Cisco 5505 firewall in it's place for testing and I am getting about 90mb x 10mb on the network.   This does not make any sense.  

 

name : wan1 vdom : root cli-conn-status : 0 mode : static dhcp-relay-service : disable ip :************************ allowaccess : https ssh fgfm fail-detect : disable pptp-client : disable arpforward : enable broadcast-forward : disable bfd : global l2forward : disable icmp-redirect : enable vlanforward : disable stpforward : disable ips-sniffer-mode : disable ident-accept : disable ipmac : disable subst : disable substitute-dst-mac : 00:00:00:00:00:00 status : up netbios-forward : disable wins-ip : 0.0.0.0 type : physical netflow-sampler : disable sflow-sampler : disable scan-botnet-connections: disable sample-rate : 2000 polling-interval : 20 sample-direction : both explicit-web-proxy : disable explicit-ftp-proxy : disable tcp-mss : 0 inbandwidth : 0 outbandwidth : 0 spillover-threshold : 0 ingress-spillover-threshold: 0 weight : 0 external : disable devindex : 5 description : alias : TimeWarner l2tp-client : disable security-mode : none device-identification: disable lldp-transmission : vdom fortiheartbeat : disable estimated-upstream-bandwidth: 0 estimated-downstream-bandwidth: 0 vrrp-virtual-mac : disable vrrp: role : undefined snmp-index : 2 secondary-IP : disable auto-auth-extension-device: disable ap-discover : enable fortilink : disable ipv6: ip6-mode : static ip6-allowaccess : ip6-reachable-time : 0 ip6-retrans-time : 0 ip6-hop-limit : 0 dhcp6-prefix-delegation: disable delegated-prefix : ::/0 preferred-life-time : 0 valid-life-time : 0 delegated-DNS1 : :: delegated-DNS2 : :: ip6-address : ::/0 ip6-send-adv : disable autoconf : disable dhcp6-relay-service : disable dhcp-relay-ip : dhcp-relay-type : regular macaddr : **************** speed : auto mtu-override : disable wccp : disable drop-overlapped-fragment: disable drop-fragment : disable

 

Toshi_Esumi
Esteemed Contributor III

The CLI you want to use is "diag hard device nic wan1". You need to specify individual port for inside interface like internal1. But if you swapped the 60D with C5505 to have ISP<->C5505<->C3750<->PC, the problem is likely between 60D and C3750. Check the speed/duplex they synced up each other on both sides.

MikePruett

Yeah, check for errors and things of that sort on the interfaces. It could be something as simple as cables etc. 60D should be able to handle that bandwidth as long as it isn't running full UTM.

Mike Pruett Fortinet GURU | Fortinet Training Videos
Labels
Top Kudoed Authors