Technical Tip : How to avoid MSS mismatch
Description
This article describes how to solve the MSS (Maximum Segment Size) mismatch. The size of the MSS can be changed according to the policies of the FortiGate.
Scope
FortiGate.
Solution

Based on the previous diagram:
If the issue occurs when a user on the internal tries to visit a site on 'web server.
On policy from “internal” to “internet”
configure firewall policy
edit x
set tcp-mss-sender 1300
end
edit x
set tcp-mss-sender 1300
end
Clear all sessions with these IP addresses.
For considerations regarding changes to MSS behavior and values, please refer to the notes in the KB article: Technical Tip: Setting TCP MSS Value