Chronicle No. 70 · Incidents
When the Internet Wasn't Slow: A Firewall at 99%
Guests at a Western Ghats resort reported dropping Wi-Fi. The bandwidth was there and the ISP links were clean — the problem was the device in between, quietly drowning in traffic nobody had asked for.
It was an ordinary busy day at the resort when the calls started.
"The internet is very slow."
"The connection keeps disconnecting."
"The Wi-Fi is connected, but nothing is loading."
It sounded like a routine connectivity problem, so I began where everyone begins. I coordinated with the ISP vendor and checked bandwidth utilisation. We tested the links, measured performance, and asked whether the available bandwidth was simply not enough. We went as far as considering a change of ISP and a bandwidth upgrade.
Then came the part that didn't fit.
Every important parameter looked normal. The bandwidth was available. The ISP links were up. The network, on paper, was healthy.
And the problem was still there. Guests were still waiting on pages that would not load. Sessions were dropping. We were seeing packet loss.
That was the moment I stopped asking why is the internet slow and started asking a different question:
What is happening to our traffic before it ever reaches the user?
The device in the middle
I turned to the firewall.
Our FortiGate was behaving abnormally, and CPU utilisation was climbing to extreme levels. What had looked like a bandwidth problem was turning into something else entirely.
So I went into the logs and the traffic patterns, and a different picture appeared. The firewall was absorbing abnormal automated traffic from the WAN side — a steady volume of suspicious requests and failed login attempts. It was inspecting all of it, and the load was enormous.
At one point CPU utilisation touched 99%. We also hit an httpsd crash, which added a layer of its own.
Suddenly the symptoms made sense. The bandwidth was not the problem. The ISP was not the problem. The one device responsible for inspecting, controlling and protecting every packet on our network was being held under water by traffic nobody at the resort had asked for.
A guest complaint about slow Wi-Fi had become a network security investigation.
We worked through the firewall configuration and the logs, analysed the traffic, and brought in the vendor and the Fortinet support team. The case was eventually escalated to FortiCare.
What it taught me
Not every internet problem is an internet problem.
Sometimes the bandwidth is fine, the ISP is fine and the access points are fine — and somewhere between the internet and the guest, something else is consuming the resources needed to deliver that connection.
That is why troubleshooting cannot stop at the first layer:
- Check the ISP
- Check the bandwidth
- Check the LAN
- Check the Wi-Fi
- Check the firewall
- Check the logs
And most importantly: look at behaviour, not only at numbers. The parameters stayed normal right through this incident. The network did not.
The guests never knew the firewall was under abnormal load. They didn't need to. They only knew their internet wasn't working.
That is what makes hospitality IT different. Our job is not simply to keep systems running. It is to make sure the technology behind the guest experience stays available, secure and reliable — and to notice when it quietly stops being any of the three.
That day I went looking for a slow internet connection. What I found was a security problem hiding behind a set of perfectly normal readings.
The hardest problems in IT are rarely the ones that throw an obvious error. They are the ones where everything looks right and something is still wrong. That is where experience matters: stay curious, question the obvious, and never accept the first answer.
Behind every alert, every log line and every traffic graph are real people waiting for the technology to simply work.
We don't just troubleshoot technology. We protect the experience it enables.
“Not every internet problem is an internet problem.”
Lesson: Normal parameters are not the same as a healthy network. When the readings look fine and the guest experience does not, keep moving inward — the bottleneck is often the device you trust most.


