Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
mtousignant
New Contributor

FortiAnalyser 400B - How powerful was this guy?

Hey folks. Just trying to figure out if this needs to be retired or needs some troubleshooting love. 400B with drive. 

 

We have it taking in logs from 2 Datacentres w/ Gate + Mail + WAF and 7 remote sites with just gates. 

It gets about 1.9GB of logs a day @ a rate of about 35 logs per sec. 

 

I just recently nuked the data on it, upgraded to the latest and readded all our devices. 

 

That was 2 months ago. We use this very rarely, mostly for 1 off pulls for specific issues, maybe 1 or 2 times a month. It's more in place for compliance. But those 1 of pulls are near unusable these days. I am waiting 8+ hours for a "Web usage report" for 7 days on 1 user @ 1 device. 

 

Are we just overloading this oldy, or is something else prolly up? Or are our expectations on using this wrong, is the normal use queuing up reports and getting them in the morning? 

 

Thanks in advance!

4 REPLIES 4
abelio
Valued Contributor

Hi,

well I have one too; it cannot run 5.2x software; latest firmware for it is 5.0.11

You can use it for reports even logging fortiOS 5.2x, living with 5.0.11 features.

1.9GB of logs a day and rate of about 35 logs per sec are not so bad.

Maybe you could reindex database to regain perfomance. (exec sql-local rebuild-db) and re-try.

Do a search for hzhao_FTNT 's recent posts to get the complete recommended sequence of commands he posted weeks ago.

 

i hope it helps

 

 

 

regards




/ Abel

regards / Abel
mtousignant

Thanks sir, I appreciate the response.

 

We are T/Sing right now with Fortinet for what looks like an HDD failure. So I think that might explain the performance issues haha.

bartman10

Just a thought.. something old like that, I would void the warranty, open it up and see what kind of CPU and RAM it's got. Most of the FortiNet equipment I've seen uses standard PC hardware. You may find you can upgrade the ram and maybe even the CPU easily. Have a look at the drives.. I'm sure they are nothing special if they are SATA clone it to an SSD and that thing will fly. 

 

What do you have to loose? 

 

I've worked some wonders on some BlueCoat, Cisco and other UTM's long in the tooth by upgrading the hardware myself. 

Hell.. Cisco allows you to upgrade the RAM in their ASA appliances, they even give you instructions on how to do it...

 

I'd be interested in what you find when you crack it open.

300E x3, 200D, 140D, 94D, 90D x2, 80D, 40C, handful of 60E's.. starting to loose track.

Over 100 WiFi AP's and growing.

FAZ-200D

FAC-VM 2 node cluster

Friends don't let friends FWF!

300E x3, 200D, 140D, 94D, 90D x2, 80D, 40C, handful of 60E's.. starting to loose track. Over 100 WiFi AP's and growing. FAZ-200D FAC-VM 2 node cluster Friends don't let friends FWF!
bartman10

Any update on this? I did you try to upgrade the ram?

300E x3, 200D, 140D, 94D, 90D x2, 80D, 40C, handful of 60E's.. starting to loose track.

Over 100 WiFi AP's and growing.

FAZ-200D

FAC-VM 2 node cluster

Friends don't let friends FWF!

300E x3, 200D, 140D, 94D, 90D x2, 80D, 40C, handful of 60E's.. starting to loose track. Over 100 WiFi AP's and growing. FAZ-200D FAC-VM 2 node cluster Friends don't let friends FWF!
Labels
Top Kudoed Authors