Wednesday, June 20, 2007

Actual Fortinet Througput... Not so exciting

So this is what we experience through a 500A in transparent mode utilising virtual domains.

We hit 30% CPU usage with a throughput of 12.72 Mb, if we extrapolate linearly (pretty damn optimisic) we fall short of 50 Mb throughput. Not exactly the 120 Mb of AV or the 600 Mb of firewall throughput touted on their product statistics, eh?

Now this may well be our configuration or specific traffic profile (it's about 90% http). We do have AV on and IDP enabled for everything and IDP is has default settings.

So here's the formula:

Default settings + handing our config to support on multiple occasions =
gulf of discrepancy between advertised and actual throughput

That being said, support is always "shocked" to see our performance, but they have yet to show me the "make this thing run slower than molasses in January" switch that I inadvertently turned on.




No comments: