Skip to main content
Bgoines
New Member
August 8, 2014
Question

VPN High Latency

  • August 8, 2014
  • 5 replies
  • 9269 views
I have a FG 110C at my main location with a 50/50 mbs fiber connection as my isp. I have a fortigate 60c at my remote locations. At 2 of the locations in question, I have 5mb/5mb pipes. These two locations have higher latency (60ms) to my main location that my other two locations with 3mb pipes (15ms). Could there be a problem with my ipsec vpn tunnels? The two locations in question have very low latency to locations such as Google or yahoo or any other website. The only time that there is high latency is from site to site.

    5 replies

    ede_pfau
    SuperUser
    SuperUser
    August 8, 2014
    The only thing that crossed my mind is " what if IPsec traffic is not accelerated on the remote FGTs?" . You can check that easily from the CLI.
    Bgoines
    BgoinesAuthor
    New Member
    August 8, 2014
    What is the command for this?
    emnoc
    New Member
    August 8, 2014
    Yes the following cmd show soft vrs hardware process FG100C3G08338342 # get vpn ipsec stats crypto IPsec crypto devices in use: CP6 (encrypted/decrypted): null: 0 0 des: 0 0 3des: 11095399 5680328 aes: 2190 2190 CP6 (generated/validated): null: 0 0 md5: 0 0 sha1: 11097589 5682518 sha256: 0 0 4: 0 0 5: 0 0 SOFTWARE (encrypted/decrypted): null: 0 0 des: 0 0 3des: 0 0 aes: 0 0 SOFTWARE (generated/validated): null: 0 0 md5: 0 0 sha1: 0 0 sha256: 0 0 4: 0 0 5: 0 0 Unless you disable it from the vpn config, the FGT110 should process these via the CP6 ASIC. btw this is 4.3p17 on a FGT110C with approx 7 active tunnels or more get vpn ipsec stats tunnel tunnels total: 8 static/ddns: 8 dynamic: 0 manual: 0 errors: 1 selectors total: 12 up: 7
    Bgoines
    BgoinesAuthor
    New Member
    August 8, 2014
    These are my results... MROUTER # get vpn ipsec stats crypto IPsec crypto devices in use: CP6 (encrypted/decrypted): null: 0 0 des: 0 0 3des: 1128807026 969056953 aes: 0 0 CP6 (generated/validated): null: 0 0 md5: 0 0 sha1: 1128807026 969056953 sha256: 0 0 4: 0 0 5: 0 0 SOFTWARE (encrypted/decrypted): null: 0 0 des: 0 0 3des: 0 0 aes: 0 0 SOFTWARE (generated/validated): null: 0 0 md5: 0 0 sha1: 0 0 sha256: 0 0 4: 0 0 5: 0 0
    emnoc
    New Member
    August 8, 2014
    Okay nothing is kicked up to the CP6 and my bad the NPU offloading is not available in a FGT110C. So you can rule out any thing handle within software per-se.
    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.