Thursday, May 14, 2009

Fortigate and SNMP graphs are broken

For some time I have suspected that Fortigate firewalls does not return the right SNMP value for traffic statistics on VLAN interfaces.

A graph

I asked Fortinet support. This is the answer I got:

Actually this is due to NP2 accelerated traffic. Only part of this traffic is seen by the main CPU (mainly the first and last packets of the session) and therefore traffic statistics for vlan interfaces can only report these packets which are seen by the main CPU.

Statistics on physical ports and aggregate ports are correctly collected because these are low-level statistics. Many vlan interfaces can be bound to the same physical or aggregate port. So, dispatching traffic statistics between these vlan can only be done if the traffic goes through the main CPU.

FortiOS allows to disable NP2 acceleration (for tests purposes). As soon as NP2 acceleration is disabled then statistics on vlan interfaces is consistent with the actual traffic.

There is no way to collect these statistics from the NP2. It can't be fixed.

My question is why support SNMP when it is broken???

Labels:

0 Comments:

Post a Comment

Links to this post:

Create a Link

<< Home