Fortinet white logo
Fortinet white logo

Administration Guide

SD-WAN Underlay Bandwidth and Quality Monitoring service

SD-WAN Underlay Bandwidth and Quality Monitoring service

The SD-WAN Underlay Bandwidth and Quality Monitoring Service bundles a set of tools and services designed to enhance the experience of deploying SD-WAN on the FortiGate. The tools can be sorted into two categories:

Application performance and configuration

Service

Overview

License

Application performance monitoring

Provides passive monitoring of common TCP metrics for each application and calculates application-level network performance metrics over multiple traffic sessions.

Requires a valid SD-WAN Underlay and Application Monitoring license.

SD-WAN Setup wizard

Step through the configurations needed to provision a basic SD-WAN setup, including interface, networking, performance SLA, and SD-WAN rule settings

Requires a valid SD-WAN Underlay and Application Monitoring license.

FortiGuard SLA database for SD-WAN performance SLA

Includes popular SaaS and Internet destinations, as well as recommended settings that you can select as probe servers for SD-WAN Performance SLA configurations

Requires a valid SD-WAN Underlay and Application Monitoring license.

Speed tests

Speed tests can be conducted either on-demand or according to a predetermined schedule, measuring upload and download speeds of up to 1 Gbps. The results of the tests can be used as reference for various applications, including the following:

  • Configuring the estimated bandwidth of an interface, which can be employed in conjunction with various WAN intelligence strategies. See Using speed test results with SD-WAN for more information.

  • Configuring the inbandwidth and outbandwidth of an interface for use in traffic shaping. See Using speed test results with traffic shaping for more information.

  • Applying the speed test to dialup VPN tunnels in a hub and spoke deployment to conduct traffic shaping.

FortiOS offers a variety of methods for testing SD-WAN speed. The following table provides a brief overview of each method and guidance on when it might be most advantageous to use one method over the others.

Service

Overview

License

CLI speed test

  • Provides the most flexibility and options, which enables the speed test to operate with user-defined parameters.

  • Results can be used as reference to manually add to the interface's estimated bandwidth, or inbandwidth and outbandwidth.

  • Server is on the cloud, which is maintained by Fortinet.

Requires a valid SD-WAN Underlay and Application Monitoring license.

GUI speed test

  • Downloads the speed test server list automatically.

  • Results can be added to the interface's estimated bandwidth with one click.

  • Results are automatically updated in the interface measured-upstream-bandwidth and measured-downstream-bandwidth fields.

  • Results can be used as a reference to manually configure an interface’s inbandwidth and outbandwidth.

  • Easier to use.

  • Server is on the cloud, which is maintained by Fortinet.

Requires a valid SD-WAN Underlay and Application Monitoring license.

Scheduled interface speed test

  • Speed tests can be scheduled to run automatically.

  • Results are automatically updated in the interface measured-upstream-bandwidth and measured-downstream-bandwidth fields.

  • Results can be used as a reference to manually configure an interface’s inbandwidth and outbandwidth.

  • Possible to temporarily bypass the bandwidth limits set on the interface and configure custom maximum bandwidth limits.

  • Server is on the cloud, which is maintained by Fortinet.

Requires a valid SD-WAN Underlay and Application Monitoring license.

Speed test from hub to spoke

  • Server is the spoke.

  • Tests initiated from the hub.

  • Results are cached for future use.

  • Results can be dynamically applied to the dialup tunnel for egress traffic shaping.

  • Results can be used as a reference to manually configure an interface’s inbandwidth and outbandwidth.

License not required.

Speed test from spokes to hub

  • Server is the hub.

  • Tests initiated from spokes, even when a spoke is behind a NAT device.

  • Results are cached on the spoke for future use and sent to the hub.

  • Results can be dynamically applied to the dialup tunnel for egress traffic shaping.

  • Results can be used as a reference to manually configure an interface’s inbandwidth and outbandwidth.

License not required.

SD-WAN Underlay Bandwidth and Quality Monitoring service

SD-WAN Underlay Bandwidth and Quality Monitoring service

The SD-WAN Underlay Bandwidth and Quality Monitoring Service bundles a set of tools and services designed to enhance the experience of deploying SD-WAN on the FortiGate. The tools can be sorted into two categories:

Application performance and configuration

Service

Overview

License

Application performance monitoring

Provides passive monitoring of common TCP metrics for each application and calculates application-level network performance metrics over multiple traffic sessions.

Requires a valid SD-WAN Underlay and Application Monitoring license.

SD-WAN Setup wizard

Step through the configurations needed to provision a basic SD-WAN setup, including interface, networking, performance SLA, and SD-WAN rule settings

Requires a valid SD-WAN Underlay and Application Monitoring license.

FortiGuard SLA database for SD-WAN performance SLA

Includes popular SaaS and Internet destinations, as well as recommended settings that you can select as probe servers for SD-WAN Performance SLA configurations

Requires a valid SD-WAN Underlay and Application Monitoring license.

Speed tests

Speed tests can be conducted either on-demand or according to a predetermined schedule, measuring upload and download speeds of up to 1 Gbps. The results of the tests can be used as reference for various applications, including the following:

  • Configuring the estimated bandwidth of an interface, which can be employed in conjunction with various WAN intelligence strategies. See Using speed test results with SD-WAN for more information.

  • Configuring the inbandwidth and outbandwidth of an interface for use in traffic shaping. See Using speed test results with traffic shaping for more information.

  • Applying the speed test to dialup VPN tunnels in a hub and spoke deployment to conduct traffic shaping.

FortiOS offers a variety of methods for testing SD-WAN speed. The following table provides a brief overview of each method and guidance on when it might be most advantageous to use one method over the others.

Service

Overview

License

CLI speed test

  • Provides the most flexibility and options, which enables the speed test to operate with user-defined parameters.

  • Results can be used as reference to manually add to the interface's estimated bandwidth, or inbandwidth and outbandwidth.

  • Server is on the cloud, which is maintained by Fortinet.

Requires a valid SD-WAN Underlay and Application Monitoring license.

GUI speed test

  • Downloads the speed test server list automatically.

  • Results can be added to the interface's estimated bandwidth with one click.

  • Results are automatically updated in the interface measured-upstream-bandwidth and measured-downstream-bandwidth fields.

  • Results can be used as a reference to manually configure an interface’s inbandwidth and outbandwidth.

  • Easier to use.

  • Server is on the cloud, which is maintained by Fortinet.

Requires a valid SD-WAN Underlay and Application Monitoring license.

Scheduled interface speed test

  • Speed tests can be scheduled to run automatically.

  • Results are automatically updated in the interface measured-upstream-bandwidth and measured-downstream-bandwidth fields.

  • Results can be used as a reference to manually configure an interface’s inbandwidth and outbandwidth.

  • Possible to temporarily bypass the bandwidth limits set on the interface and configure custom maximum bandwidth limits.

  • Server is on the cloud, which is maintained by Fortinet.

Requires a valid SD-WAN Underlay and Application Monitoring license.

Speed test from hub to spoke

  • Server is the spoke.

  • Tests initiated from the hub.

  • Results are cached for future use.

  • Results can be dynamically applied to the dialup tunnel for egress traffic shaping.

  • Results can be used as a reference to manually configure an interface’s inbandwidth and outbandwidth.

License not required.

Speed test from spokes to hub

  • Server is the hub.

  • Tests initiated from spokes, even when a spoke is behind a NAT device.

  • Results are cached on the spoke for future use and sent to the hub.

  • Results can be dynamically applied to the dialup tunnel for egress traffic shaping.

  • Results can be used as a reference to manually configure an interface’s inbandwidth and outbandwidth.

License not required.