Skip to main content
GGTeleconsul
New Member
February 22, 2019
Question

Same data stream loss on IPSEC VPN between 2 Fortigate FW

  • February 22, 2019
  • 1 reply
  • 2515 views

Hi,

i have a IPSEC Routed VPN between 2 Fortigate and for one week it happens that same protocols have problem with data stream such as SSH, VNC and RDP if the connection starting from one network, but it's ok from other network.

 

--------A-----------                 |------------------VPN---------------|                   ---------B---------

|  192.168.2.0/24 |-----------FG A ----------| INTERNET |---------FG B-----------|  192.168.0.0/24 |

--------------------                                    --------------                                   --------------------

 This VPN is ok since six years.

 

All connections from B network to A network is ok

Same connections from A network to B network have fails: 1) Ping is ok

2) SSH login is ok, but others commands (like 'ls -lah') fails

3) Same VNC connections is ok (tightVNC), others (Windows CE VNC or Embedded Linux Thin Terminal VNC) dead on data stream

4) SFTP fails ever

5) http and https on B devices (switch, FG B) fails

 

It could be an MTU problem?

any other suggests?

 

 

 

 

 

 

1 reply

Toshi_Esumi
SuperUser
SuperUser
February 22, 2019

Sounds like it. Have you tried pinging with a large size packets like 2000 both outside and inside the tunnel? Did the fragmentation work for both cases? Since those are all TCP applications, try like "set tcp-mss 1300" on the interface. I

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!