Skip to main content
the_rock
Explorer III
October 18, 2023
Question

Very slow responses to anything internal when connected to ssl vpn

  • October 18, 2023
  • 10 replies
  • 9990 views

Hey guys,

 

Please bear with me here, as I work way more with couple other vendors, though I would say Im fairly verse when it comes to Fortinet : - ). Anyway, here is the scenario. Customer purchased 2 brand new 200F firewalls and we have really odd problem and my colleague (who btw is real Fortigate guru) are having heck of a time trying to fix this problem. Essentially, even if single person is connected to ssl vpn, responses to anything internal are real slow and ping times can go up to 2000 seconds. We tried failover, no luck, disabled assic offload for ssl vpn rule, tested multiple barebone forticlient versions (no luck), enabled DTLS tunnel option, same issue.

Now, there are only maybe 6-7 security rules configured, so its super basic. We even have TAC case open for this for about a week, but since they cant replicate it, guy suggested to try reboot the current primary firewall. I have no clue if that will help, as it has been up for only 35 days, but it would need to be scheduled with the customer.

 

Also, maybe worth pointing out, ssl vpn rule does NOT have any security profiles configured at all.

 

This week, I attempted things from below posts, but same issue persists.

 

Troubleshooting Tip: ‘SSL-VPN slow file transfer ... - Fortinet Community

 

Solved: SSL VPN poor speed - Fortinet Community

 

Fortigate slow SSL VPN throughput : r/networking (reddit.com)

 

Current version is 7.2.5

Any help/suggestions are welcome and highly appreciated!

 

Thanks so much in advance.

Kind regards.

 

 

10 replies

DanNSits
Explorer III
October 18, 2023

Hi Andy,

if TAC cannot replicate it, can you replicate it in a lab to be able to further troubleshoot it without having to ask the customer for maintenance windows?

the_rock
the_rockAuthor
Explorer III
October 18, 2023

Hey Danny,

Well, when I test this from my own work laptop or even my personal desktop, I have exact same issue.

Andy

DanNSits
Explorer III
October 18, 2023

Perfect. So reboot your lab firewall that shows the same symptoms and you are able to reply to TAC.

Yurisk
SuperUser
SuperUser
October 29, 2023

Hi, sorry for the late reply, I see 2 ways - Short one and Long one, I'd start with the Short.

Short:

  • Upgrade to 7.2.6, on 10th of October Fortinet released PSIRT alert on versions including 7.2.5 on password disclosure in SSL VPN https://www.fortiguard.com/psirt/FG-IR-23-120 so it would be a great "selling" point to the client. On the way it will do a reboot, and make sure you haven't stumbled on a hard-to-replicate bug in 7.2.5. In general, with FortiOS, the convention is to deem versions up to x.x.6 as QA releases. I've started deploying 7.2.6 and so far looks good.

Long:

  • First: there is (almost) no configuration parameter that can cause such a problem intentionally, so it is not a misconfiguration (I guess you are using FortiClient in Tunnel mode, not Web mode proxying where slowness is not a bug but a feature?)
  • Check health params on the FGT while experiencing the problem - CPU load, memory consumption. 
  • Check MTU inside the tunnel, as MTU misalignment may cause fragmentation/defrag deteriorating the connection (it is set automatically on FC connect).  
  • Try different protocols inside the tunnel - FTP/HTTP to see may be it is some specific protocol, like SMB is known to become very slow on VPNs, as opposed to FTP/HTTP.
  • Look in logs for anything outstanding 
  • run a sniffer in the FGT to look for retransmits, damaged packets, low MSS for TCP packets.  
  • Run ping inside the tunnel and compare to the ping over the clear text to the FGTs WAN IP to see if this slowness shows in the very basic ICMP traffic as well. 
yurisk.info - all things Fortinet blog, no ads
Pr0xy
Visitor III
July 18, 2026

I just posted this in another thread and it may apply here: Sometimes depending on the upgrade (or change) and how you do it you could enable new features that may impact performance.  It typically isn’t the appliance, its something else… but remember you’re only as fast as your slowest connection/process.  One thing I'd check is whether if any change (esp. upgrades) introduced a configuration or processing change rather than an appliance performance issue. A few areas I'd investigate:

  • Definitely check the IPv6 Settings and any configuration changes. Confirm IPv6 isn't introducing routing, DNS, or other added processing overhead, like policy-processing.
  • Check logging - add anything? extend anything?  did you add sync?  Are you hitting max and overwrites are taking longer? Logging and HA synchronization absolutely increases logging, cloud logging, or session synchronization which can add latency.
  • Check if you moved anything to Cloud services (processing, auditing, logging), this would absolutely slow things down if they were all internal.  
  • Check Carrier dependencies like HW acceleration/NPU offload status with some FortiOS upgrades can alter acceleration-related settings, causing VPN traffic to be processed in software instead of hardware.
  • Check the SSL inspection and security profiles applied to VPN traffic.  Anything added or changed?  if you’re not sure, you can temporarily test with SSL inspection, IPS, AV, and other UTM profiles removed to isolate overhead.  MTU/MSS and fragmentation. can be related.
  • Check QoS, SD-WAN, or traffic-shaping policies. Verify VPN traffic is still being prioritized as expected.

Given that performance was normal before, I'd focus on identifying a feature, inspection profile, acceleration setting, or processing path that changed before assuming it's a hardware limitation or consider downgrading or upgrading.  I always do a compare and check the forums for things like this and hope someone had a similar experience and can share.  Thanks to all of you who do!

So Sayeth the Pr0x1
Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!