Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
axlmac
New Contributor

Traffic shaping

Hi folks,

 

I'm struggling at defining trafic shaping policies and even with a Fortinet engineer it seems harder and more difficult than climbing the Everest mountain. In my case I want to limit at 600/150 DL/UL and I get variable results, meaning for ther DL is always at around 360Mbps whereas for 150Mbps shaper we get something between 95 and 120 Mbps. I have read on this forum, threads quite old though (i.e. more than 10 years ago), that Fortinet doesn't excel at traffic shaping and the knowledge is just with FortiOS devs.

Shall we nowadays confirm the same (not good) evaluation for this feature on Fortigates? Thanks Alex

3 REPLIES 3
Toshi_Esumi
SuperUser
SuperUser

Although I tend to agree with your assessments and most of Fortinet TAC are not trained how diffserv-based QoS should work, the shaper/shaping-policy itself is relatively simple if you understand concept of shared vs. per-policy shapers and the direction of sessions + shaper/shaper-reverse. Still problem with FortiOS is there isn't any good command to verify/see if shapings are working in intended way. Probably because FGT is a "firewall", not a "router" like Cisco, Juniper, etc.

Please share some key parts of your shapers and shaping-policies you laid out.

axlmac

Hi Toshi Esumi,

 

thanks for your reply. I have just got the reply from the Fortinet's engineer wit hthe proof that he was able to accuretely limit the flows at 1Mbps, 2Mbps, 10Mbps and 20Mbps. I will carefully review and compare his configuration with mine. For the moment I can say, just to spot differences during the troubleshooting process, that my limits are way higher and my interfaces are on the LAN side a VLAN on a LACP trunk and a EMAC-VLAN on a trunk LACP on the WAN side and tests are done within a VDOM. The Fortios version is 6.2.4 and LACP was just introduced in 6.2 for models like 60E that we use. I will keep you posted,

 

Alex

lobstercreed
Valued Contributor

I don't have a lot of experience with shaping (don't need it or find it cost-effective for the most part), but I agree with Toshi that the configuration is fairly straight-forward as long as you pay attention to key concepts.  I would also recommend watching the SD-WAN videos specifically covering traffic shaping that are free on training.fortinet.com

 

I think your issue is the box you're running it on.  Some of the values you've stated are higher than the capacity of the 60E depending on what features you have turned on, so it's likely that it's maxed out.  Try lower shaping values and see if it works as expected before blaming the shaping.  Besides, shaping is meant to keep the traffic *below* a certain speed.  Nothing will happen if the traffic can't reach those maximums in the first place.

Labels
Top Kudoed Authors