Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Kenny_Verhaege
New Contributor

Slow HTTP(S) traffic

Dear,

 

We have migrated 2 sites from MPLS to a S2S VPN, now making use of Fortinet Firewalls 60-90D.

In one site, everything works well (40Mbps internet line). When we do tests on site with a user directly connected to internet, we have normal speed. Once we connect the user via the firewall the speed of internet (HTTP/HTTPS) is very very slow. 

We tried routing HTTP/S with local outbreak of via S2S, makes no difference.

Citrix traffic (over S2S to HQ) is running smooth. Within Citrix session HTTP/HTTPS is running smooth.

So definitely some configuration issue / firmware issue within firewall.

 

Webfilter, antivirus, ... has been disabled. Any ideas are welcome.

 

Kenny

1 REPLY 1
makco10
Contributor II

Hello,

 

The Fortigate have two inspection modes Flow-based and Proxy.

 

Each inspection component plays a role in processing traffic on it's way to its destination. Having control over flow-based and proxy-based mode is helpful if you want to be sure that only flow-based inspection mode is used (and that proxy inspection mode is not used).

 

In most cases, proxy mode is preferred because more security profile features and more configuration options are available. However, some implementations require all security profile scanning to use only flow-based inspection mode for highest possible throughput.

 

Fow-based mode is  designed to optimize performance.

 

https://help.fortinet.com/fos50hlp/56/Content/FortiOS/fortigate-getting-started/7-inspection-mode/fl...

 

Regards.

 

Defend Your Enterprise Network With Fortigate Next Generation Firewall
Defend Your Enterprise Network With Fortigate Next Generation Firewall
Labels
Top Kudoed Authors