Skip to main content
marugby
New Member
July 4, 2016
Question

Throughput of SSL VPN and Passthrough SSL VPN

  • July 4, 2016
  • 7 replies
  • 18603 views

Hello All,

 

I am in desperate need for assistance. I have an 80C as my perimeter firewall, and an ASA 5505 directly connected behind it.

 

[Internet] > 80C > ASA (DMZ)

 

Previously, the 5505 used to be the perimeter, and users would connect with AnyConnect for SSL VPN access, with zero issues with throughput (getting maximum bandwidth over the VPN) or MTU size. Now they are experiencing two issues:

 

1) AnyConnect gives an error about MTU size being too low and disconnects. I have confirmed my end-users' machine's interface MTU is set to 1500, the interface on the ASA is set to 1500, and have set the "set tcp-mss-sender 1452" on the passthrough policies on my 80C on each of the policies for the passthrough traffic, but still users get disconnected because of MTU.

2) Throughput over the VPN is far from the maximum 70mbps that 80Cs can handle (getting about 3-4mbps). I have confirmed this via my phone, as well as my laptop over many different connections to ensure the connection I was using wasn't causing the issue.

 

As a fix, I configured SSL VPN on the 80C, and don't have the MTU issue, but throughput is still dog slow (about 10% of what the speed should be). What I find weird is: if I connect off one of the internal ports (essentially, my LAN) via AnyConnect to the ASA (so LAN > DMZ), I get no MTU issues and full throughput.

 

I have no security profiles on the policies for the passthrough traffic to ensure that is not bottlenecking anything, but the fact that I have the throughput issues on AnyConnect and FortiClient is puzzling. 

 

Finally, I had a spare 80C that I spun up and only configured the passthrough SSL VPN and the Fortigate's SSL VPN and still have the same issue, so I have confirmed it is not the unit.

 

Is this due to the fact that the ASA is using the designated "DMZ" port? Or is there something I am missing.

 

Any help would be greatly appreciated.

Thank you.

7 replies

marugby
marugbyAuthor
New Member
July 9, 2016

Anyone have any insight into this?

 

I will note that I realized I never PAT'd UDP 443 for DTLS, so the AnyConnect VPN throughput is up to about 25mbps download and about 15mbps upload, but I would rather use FortiClient and remove the ASA's VPN altogether.

kallbrandt
New Member
July 10, 2016

What kind of ISP connection do you have?

Post the config of the 80C here and I'll take a look.

 

emnoc
New Member
July 10, 2016

What i would do is to look for errors on any interfaces on the FGT

 

e.g ( wan1 & dmz interface )

 

diag hardware  deviceinfo nic wan1 | grep rror

diag hardware  deviceinfo nic dmz1 | grep rror

diag hardware  deviceinfo nic wan1 | grep peed

diag hardware  deviceinfo nic dmz1 | grep peed

 

2nd,

 

1) AnyConnect gives an error about MTU size being too low and disconnects. I have confirmed my end-users' machine's interface MTU is set to 1500, the interface on the ASA is set to 1500, and have set the "set tcp-mss-sender 1452" on the passthrough policies on my 80C on each of the policies for the passthrough traffic, but still users get disconnected because of MTU.

 

The above bold is not going to be helpful on the  SSL encrypted tunnel traffic, thought I would point that out

 

3rd,

 

Do be quick to rule the FGT80C as the culprit. We had a similar issue but with a 310 and after we introduce it  our problem boil down that at the same time we place the  FGT and a  ASA downstream that our ISP had traffic issues and was dropping  tcp and specifically HTTPS traffic. I would place a anyconnect cliet on the "perimeter" interface of the   FGT80C and see if the performance increases or decrease.

 

 

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!