Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
sims
New Contributor III

Bandwidth Internet

Hi,

I have 50 mbps  internet bandwidth . Server Administrator is always complaining about the internet bandwidth .

When he download files it never cross  above 3 Mbps. 

In traffic Shaping I have prioritized this traffic and given full bandwidth . 

Though the server not getting more than 3 Mbps.

Q1. What will be the default policy If I did not create any particular traffic shaping policy ?

Q2.How To check why the traffic is not increasing 

 

Thanks

6 REPLIES 6
rwpatterson
Valued Contributor III

A couple of things to check:

1) Are you getting errors on the interface?

   I believe the command to check is >dia sys har nic wanx <- interface name here

2) Are both sides of your WAN connected at the same duplex?

3) Are you getting fragmented packets?

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
sims
New Contributor III

A couple of things to check: 1) Are you getting errors on the interface?    I believe the command to check is >dia sys har nic wanx <- interface name here

no errors  2) Are both sides of your WAN connected at the same duplex?

same duplex  3) Are you getting fragmented packets?

How to check  fragmented packets?

Tahnks for your help 

Dave_Hall
Honored Contributor

I would also add to check the other side of the connection from the server admin's pc to the fgt and anything in between. 

 

Though, I can't see under any circumstances the connection being that slow from the server admin pc to the Internet unless there something like either packet lost, full blown UTM/IPS packet inspection enabled on the connection and/or traffic shaping misconfigured, possible maxed throughput.

 

If would help if you let us know what model and firmware the fgt is running - if the firewall policies are divided up to cover various type of traffic or a single one firewall policy.  If traffic shaping is involved - how is it set up?  (any set for guaranteed bandwidth?)  Has ingress egress values been set up on the WAN interface?

 

NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C

NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C
sims
New Contributor III

Hi dave

Thanks for the reply .

Here is my traffic shaper -Reverse shaper .

Do I need to  set guaranteed Bandwidth ? If yes What is the optimum value .

My requirement is  the server should get 10MBps(MegaByte) File download speed 

Shared Name 100-Meg-Shared Traffic Priority High 100000 Guarantee Bandwidth : Nothing 

How to check UTM/IPS packet inspection is full blown ? 

Thanks

 

 

 

 

sw2090
Honored Contributor

Are you using sd-wan?

If so the load balancing could be the culprit. Due to the balancing algorithm you could be balancedonto a slow wan then even though you have a traffic shaper on the policy.

In this case I would suggest a sd-wan rule instead of the shaper to priorize that traffic with guaranteed bandwith.

-- 

"It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams

-- "It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams
sims
New Contributor III

Hi,

I am not using sd-wan

Thanks

Labels
Top Kudoed Authors