← Back to knowledge base
medium

Troubleshooting SD-WAN bandwidth and network monitoring speed tests

Confirmed 8/8/2026

Problem

The licensed SD-WAN Bandwidth/Network Monitoring Service measures interface bandwidth by running a speed test against a Fortinet-maintained cloud server. The results can be used to configure interface bandwidth for traffic shaping. A test may fail when licensing, internet connectivity, DNS resolution, system time, server-list retrieval, cloud connectivity, or ECMP routing is incorrect.

Symptoms

The speed test does not start or complete successfully; the speed-test server list cannot be downloaded; `execute speed-test-server download` returns `Download timeout.`; forticldd reports connection timeout, connection refusal, or failure to reach productapi-svr; or packet captures show traffic leaving through the wrong interface.

Environment

FortiGate devices with a valid SD-WAN bandwidth monitoring license. In an HA deployment, every FortiGate member must have the license. The ECMP-specific server-list download issue applies to FortiOS 7.2.

FortiOS version

FortiOS 7.2; ECMP issue resolved in FortiOS 7.4.1.

Root Cause

Possible causes include an unlicensed HA member, lack of internet access through the tested interface, failure of system DNS to resolve `productapi.fortinet.com`, a FortiGate clock difference greater than 10 seconds from the cloud server, an invalid or stale speed-test server list, blocked HTTPS connectivity to the cloud service, or ECMP selecting the wrong egress interface. In the FortiOS 7.2 ECMP scenario, there is no option to specify an outgoing source IP when downloading the speed-test server list.

Solution

  1. Confirm HA licensing. If the FortiGate is part of an HA cluster, verify that every HA member has an SD-WAN bandwidth monitor license. The test fails if only one member is licensed.

  2. Test internet and DNS connectivity. Confirm that the FortiGate can access the internet from the interface on which the speed test will run. Verify that system DNS can resolve and reach the Fortinet product API:

execute ping productapi.fortinet.com
  1. Validate system time. Ensure the FortiGate clock is current. A difference greater than 10 seconds between the FortiGate and the cloud server can prevent authentication. Synchronize the FortiGate with an NTP server to correct the time difference.

  2. Refresh the speed-test server database. Remove the existing server entries and download a new list:

config system speed-test-server
purge
y
end
execute speed-test-server download
  1. Review the downloaded server list and test multiple regions. Display the available regional server groups:
execute speed-test-server list

Confirm that the listed server groups are valid. Select a region exactly as shown in the output and start a test through the required interface:

execute speed-test <interface_name> <mention one region as seen from listed output>

Repeat the test against multiple regions.

  1. Collect forticldd debugging. The forticldd daemon handles this service. Enable debugging, then initiate the speed test from either the GUI or CLI:
diagnose debug reset
diagnose debug console timestamp en
diagnose debug application forticldd -1
diagnose debug enable

Inspect the output for the destination IP, TCP port 443, DNS results, timeouts, or refused connections. An example destination seen in debug output is 154.52.13.199, but this address is not static and changes frequently. Example messages may include fds_https_timeout: Connection timed out, svr=productapi-svr, fds_send_reply: send reply failed: req-25, Connection refused, resolution of productapi.fortinet.com, and selection of 154.52.13.199:443.

  1. Capture traffic to the current cloud-server IP. Use a GUI packet capture or run a CLI sniffer using the IP identified in the forticldd debug. For the example IP:
diagnose sniffer packet any 'host 154.52.13.199' 6 0 l

In this command, 6 is the verbosity level, 0 means an unlimited packet count, and lowercase l enables local timestamps. Start the speed test from the GUI or CLI while the capture is running.

  1. Address the FortiOS 7.2 ECMP scenario. If the server-list download times out, run:
execute speed-test-server download

A failure may appear as Download timeout. Review all routes:

get router info routing-table all

An affected ECMP routing table may contain multiple default paths, for example:

Routing table for VRF=0
S* 0.0.0.0/0 [1/0] via CVN tunnel 185.144.222.244, [1/0]
             [1/0] via DVPN tunnel 194.74.74.202, [1/0]
             [1/0] via 10.149.84.184, FER, [1/0]
             [1/0] via AZURE-VPN tunnel 20.92.14.36, [1/0]

Use the sniffer to determine whether the request is leaving through the wrong interface. The server-list download does not provide a way to select an outgoing source IP. For the speed test itself, select the outgoing interface with:

execute speed-test <interface><region>

Configure a static route for the server IP identified in the forticldd debug through the required interface. Because the server IP changes frequently, use the current debug result. The underlying ECMP issue is resolved in FortiOS 7.4.1.

Verification

Confirm that execute speed-test-server download completes without Download timeout., execute speed-test-server list displays valid regional server groups, and speed tests complete against multiple regions. Review forticldd output and packet captures to verify successful DNS resolution and HTTPS connectivity to the selected cloud-server IP over TCP port 443 through the intended interface.

Tags

No tags yet.

Community rating

— / 5 (0)

Discussion (0)

    No comments yet.