Question
Fortigate IPsec tunnel slow TCP, fast UDP
Good afternoon all, I've inherited a setup that has two locations. Fortigate1 (WAN speed 1000Mbps up/down) Fortigate2 (WAN speed 200Mbps up/down) I've ran into an issue where file transfers between the two are very slow. I tested using iperf3 and I get about 15-30Mbps no matter which side is sending/receiving. If I test using UDP, it maxes out bandwidth both ways. The tunnel is using AES128-SHA256 for phase1 and phase2. DH Group 2. I've opened a ticket with fortinet but they are pretty stumped on this. I've read similar accounts online where this was fixed by changing MTU and/or tcp-mss-receiver/sender on the policies. I've tried setting a lower tcp-mss on the incoming/outgoing policies but this has no effect. Here is an example of a similar issue I found on reddit: https://www.reddit.com/r/networking/comments/9vep0k/ipsec_speeds_are_trash_or_im_doing_something/
