Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
intuittech
New Contributor

Low Throughput on new Fortigate 100E

Configured a new Fortigate 100E at one of our colocated space in a data centre. We have got 100 Mbps dedicated pipes coming in from the provider but Fortigate WAN speed does not seem to going above 2.5 Mbps Upload/ 15 Mbps Download.

 

Fortigate 100E

FortiOS v5.6.2

All UTM features disabled

 

Already Tried

Firmware reinstall through TFTP

Reconfiguration

Set Speed WAN interface to auto, 1000full and 100full

7 REPLIES 7
Hosemacht
Contributor II

Hey there,

 

if you want to stay at FortiOS 5.6 please try the latest version (5.6.5)

there are many fixed issues.

when you say no utm features enabled then you mean also no proxy options enabled?

sudo apt-get-rekt

sudo apt-get-rekt
intuittech

By no UTM I mean all UTM features are unchecked in the policy created for Internet connectivity. It is set in basic NAT mode with a static route to the gateway of the provider.

rwpatterson
Valued Contributor III

Check the interface for errors from the cli.

 

FGT# dia har dev nic <interface name>

 

Also best practice is to force the speed and duplex and not use auto on the ingress/egress ports to outside providers.

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
Toshi_Esumi

If the actual performance is that low, it's likely duplex mismatch on the other side of the cable as rwpatterson suspects. Before changing from auto/auto, see if FGT side ended up with half-duplex. Then the other end is most likely hard-coded. If that's the case, either you have to hard-code your FGT end, or ask the other end (the vendor's device) to auto/auto. For this reason, we always set our CPE (not only FGT) side auto negotiation for all customer installations then check the duplex.  Often than not, the vendor of the other end can't/don't tell (or even lie) their equipment setting.

rickguthier

We solved a similar issue like this by unsetting netflow and unsetting the inbandwidth and outbandwidth statements that for some reason were added to the internal1 interface.  This was a 60E.  Performance went from 2.5 meg to over 200meg for fast.com and speedtest.net.  (Gig down internet service)

JamieSLH

Maybe too late to matter, but we had an almost identical issue, and nothing we did on the Fortigate helped.  We turned off all UTM features, set both our switch (a FS108D between the ISP and the FG100E) and the ISP switch to to negotiate to 100Meg manual full duplex, and still were getting sub 3meg speeds on an ISP feed rated at 100meg.

It turned out that the ISP switch was the issue - not sure if it was a hardware or firmware issue, but removing the switch between the ISP modem and the FS108D bounced our speeds from about 3 meg to over 100meg.

Maybe an isolated circumstance, but worth sharing...

 

Jamie

Jamie

Jamie
Toshi_Esumi

That almost automatically means there was a speed/duplex config mismatch on an ethernet section (or two) from the modem to the FG100E. You could have checked it at each device before fixing it by "try this, try that". 

Labels
Top Kudoed Authors