SSL VPN Performance (ssl.root mtu size)
I'm having a significant performance issues with SSL VPN vs IPSEC VPN. The specific issue is download performance. upload is blazing fast.
What have I done to troubleshoot?
1. Verified client tunnel interface MTU sizes
2. Added TCP MSS size (1240 - This seemed to offer the best download performance) adjustment to the ssl.root interface and policies with ssl interface referenced. Upload performance is 750-800 mbps...
3. Tested across multiple clients (Windows, macOS and Linux). Windows and macOS are running 7.2.1 and Linux is running 7.0.7 since anything later destroys upload and download performance for Linux users.
4. Disabling DTLS on the FW dramatically increased upload speeds across all clients and client OS types.
Now. I know FGT 7.4.1 is supposed to provide DTLS improvements and FCT 7.2.2 is supposed to provide DTLS to all client types. When this occurs TCP MSS size adjustment will be useless. I noticed the ssl.root interface has an MTU of 1500 and the mtu override and mtu adjustment commands are not available for the ssl.root interface. I've enabled ping on the ssl.root interface.
1. Does anyone have any idea how to improve download performance today?
2. How will DTLS (aka UDP traffic) not cause fragmentation issues for downloads when the ssl.root interface is set to 1500? Is there a way to change it and will Path MTU Discovery handle the MTU size for the path as it relates to downloads from over the ssl vpn tunnel aka ssl.root interface?
