Skip to main content
elyes
New Member
November 14, 2017
Question

traffic flow over IPsec very slow

  • November 14, 2017
  • 1 reply
  • 10950 views

Hello,

I have a established a VPN between a 300D and a 60D. Users are facing slowness issues.

I have noticed a weird thing! the MTU of the VPN interface is 1446 (enc 3DES) but when I ping remote machines with  datasize of 1478 it fails first then it works (ping -f -l 1478  x.x.x.x)

For me, the value shouldn't be bigger than 1418 (as the ping has size of 28 bytes.

I also tried to set MSS on both policies (in/out) on both firewalls to avoid the latency but it didn't help.

 

Can you help on this topic?

Thanks

    1 reply

    elyes
    elyesAuthor
    New Member
    November 20, 2017

    any help? 

    Sebastiaan_Koopmans
    New Member
    November 20, 2017

    Which firmware are you using in the Fortigates?

    elyes
    elyesAuthor
    New Member
    November 20, 2017

    5.4.4