Fortigate and SNMP graphs are broken
For some time I have suspected that Fortigate firewalls does not return the right SNMP value for traffic statistics on VLAN interfaces.

I asked Fortinet support. This is the answer I got:
Actually this is due to NP2 accelerated traffic. Only part of
this traffic is seen by the main CPU (mainly the first and last packets of the
session) and therefore traffic statistics for vlan interfaces can only report
these packets which are seen by the main CPU.
Statistics on physical ports and aggregate ports are correctly collected because
these are low-level statistics. Many vlan interfaces can be bound to the same
physical or aggregate port. So, dispatching traffic statistics between these
vlan can only be done if the traffic goes through the main CPU.
FortiOS allows to disable NP2 acceleration (for tests purposes). As soon as NP2
acceleration is disabled then statistics on vlan interfaces is consistent with
the actual traffic.
There is no way to collect these statistics from the NP2. It can't be fixed.
My question is why support SNMP when it is broken???
Labels: Fortinet


0 Comments:
Post a Comment
Links to this post:
Create a Link
<< Home