Skip to main content
HT_JDC
New Member
October 23, 2025
Question

Overhead for IPsec aggregation at SD-WAN

  • October 23, 2025
  • 5 replies
  • 639 views

Dear Experts,

 

I want to know the theoretical overhead of  bandwidth when IPsec aggregation is used at SD-WAN.

For example, pure WAN1: 5Mbps, pure WAN2: 3Mbps and pure WAN3: 2Mbps.

Total is 10Mbps. All WANs is IPsec-aggregated as SD-WAN.

   PC1 -- FG1(IPsec Aggregated SD-WAN) -- (network) -- FG2(IPsec Aggregated SD-WAN) -- PC2

 

We tried a little. 8-8.5Mbps between PC1 and PC2. I do not judge if it is reasonable.

 

Any comments are appreciated.

 

 

5 replies

Toshi_Esumi
SuperUser
SuperUser
October 24, 2025

Have you measured bandwidth between two FGTs 1) just over the internet on each port, and 2) a single IPsec between them on each interface? What are those numbers?

I think 2) is the deciding factor. And, I wouldn't expect much overhead by "IPsec aggregate" or "SD-WAN".
Besides, it's difficult to measure the total bandwidth over SD-WAN with 2 paths. Even if you set them to load-balance, if the source IP and destination IP is the same, the measuring traffic would take only one side of those paths.

Toshi

HT_JDC
HT_JDCAuthor
New Member
October 24, 2025

Dear Toshi,

 

Thanks for your reply. I should have clarified more.

 

The values like 5Mbps means "1) just over the internet on each port" which you are saying.

 

We use VXLAN so that PC1 and PC2 belong to the same network. iperf is used between PC1 and PC2. Thus, no load-balance exists.

 

Any additional comments would be appreciated.

 

Toshi_Esumi
SuperUser
SuperUser
October 24, 2025

In other words, you need to use iPerf test between two fortigates, for:
1) wan1 - wan1 and wan2 - wan2
2) IPsec1(interface) - IPsec1 and IPsec2 - IPsec2
https://community.fortinet.com/t5/FortiGate/Troubleshooting-Tip-Configure-FortiGate-as-speed-test-iperf/ta-p/232172
Which would be the ceiling of the max bandwidth on each path. 

I'm not sure how FGT decide which path to pass VXLAN traffic. I'm guessing that's depending on how it's configured. Afterall VXLAN need to be forwarded from IP to IP over IPsec, right? I'm not so familier with VXLAN itself. 

Toshi

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!