Skip to main content
mimetist
New Member
May 20, 2019
Question

VDOM performance impact

  • May 20, 2019
  • 3 replies
  • 5044 views

Hi,

 

I am trying to understand what will the performance impact of adding a new VDOM that will be used as site-to-site VPN concentrator. Total number of IPSec VPN tunnels will be about 100 with summary throughput up to 2Gbps. Quite possible the number of IPSec tunnels will grow in the future. Does Fortinet have any best practices for this kind of scenario? 

    3 replies

    Toshi_Esumi
    SuperUser
    SuperUser
    May 20, 2019

    Although I don't know if such documentation is available, I wouldn't expect much difference. But if NP6 supported model, make sure to follow the doc below so use the same NPU from ingress to egress of VPN traffic. That definitely affects to VPN performance.

    https://fortinetweb.s3.amazonaws.com/docs.fortinet.com/v2/attachments/e564ec10-1a20-11e9-9685-f8bc1258b856/fortigate-hardware-acceleration-60.pdf

     

    hklb
    Visitor III
    May 20, 2019

    toshiesumi wrote:

    Although I don't know if such documentation is available, I wouldn't expect much difference. But if NP6 supported model, make sure to follow the doc below so use the same NPU from ingress to egress of VPN traffic. That definitely affects to VPN performance.

    https://fortinetweb.s3.amazonaws.com/docs.fortinet.com/v2/attachments/e564ec10-1a20-11e9-9685-f8bc1258b856/fortigate-hardware-acceleration-60.pdf

     

    Hi,

     

    Do you have an explaination ? I don't understand why it would cause an impact (most of FGT has an ISF)

     

    Lucas

    Toshi_Esumi
    SuperUser
    SuperUser
    May 20, 2019

    I don't know if NPU offloading can actually happen when the ingress belongs to npu0 and the vdom-link to hand out belongs to npu1 (maybe described at somewhere in the doc). But easily understand it needed to be pulled out from the NPU back to the CPU to put back in another NPU. Then same thing needs to happen on the egress vdom if npu mismatches there as well.

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!