Fortinet 60D VPN connectivity issue.
Good day folks, I have a good one for you all.
We have recently instated a VPN with a provider of services. In short, the VPN works, however the connection is unreliable. Ping tests between the two have been sporadic at best, on average 20 - 30% packet loss. That and other connections, RPC, SSH, Telnet, RDP fail and when they do connect, timeout very quickly. I contacted our ISP to test and see if there is anything on the WAN side, but that came up clean. I just want to run down the configuration of the VPN connection to be 100% sure that it is indeed not the config nor the Fortinet causing the issue.
The Fortinet 60D has the latest update, I used the VPN wizard, and converted it to custom, and punched in the necessary Phase 1 and 2 entries. Here is where it got a bit tricky;
We have one encryption domain, 192.168.228.0/24. HOWEVER 228.0/24 had to be mip'd to 12.0/24 (factual internal range). Of course we know that you create a VIP range external 192.168.228.0/24 to 192.168.12.0/24 internal. Then create a IPpool for the one-to-one of 192.168.228.0/24.
That said, I have the source encryption domains IP pointing to the VIP range (192.168.228.0/24 to 192.168.12.0/24), any service, NAT enabled for the incoming policy.
As for the outgoing policy, I have the local subnet 192.168.12.0/24 pointed to their encryption domains, any service, NAT enabled and using the dynamic IPpool for the one-to-one addressing of 192.168.228.0/24.
My question is, could there be an issue with the way I have the VPN routed within the Fortinet back to their network? Have I missed something, as far as configuration is concerned? After some long conversation between their net admin and I, we are both at a impasse as to why the connection is so unstable.
Any input or suggestions would be very much appreciated!
