New Member
September 3, 2014
Question
Issues with Fortigate 60D IPSec VPN and packet size
- September 3, 2014
- 5 replies
- 13631 views
We have an issue with IPSec VPN tunnels to new Fortigate 60D units that we do not with the 60C model, same firmware on both and we have tested 5.0.7-9 and 5.2 issue persists in all cases on the 60D. We have a HQ running an 80C HA cluster which accepts Dialup client connections from a number of remotes site Fortigate 60C and now 60Ds. The 60D tunnels are established as normal and look OK, however we experience issues with VNC access to these sites, very slow and timing out access to the Fortigate web interface, and timing out to SSH when running commands with large output. Through flow filters and packet sniffing we have determined that the 60D appears to be dropping packets over a certain size. We can successfully send ICMP packets up to 20996 bytes to the Fortigate itself anything over is received by the 60D but no response is sent. As another test there is a printer onsite, in it' s case any ICMP request over 8192 bytes is received but nothing is sent back. I have attached the flow filter and sniffer logs. Any suggestions on settings that may have changed or are new on the 60D that may cause this? Thanks, Nathan Emerson
