Customer Service
Customer Service Information and Announcements
tonylin1
Staff
Staff
Article Id 216990
Description

This article describes how to increase the SSL-VPN tunnel mode bandwidth for small model (multi SSL-VPN client).

 

Topology:

 

iperf server <--> FortiGate (SSL-VPN) <--> sslvpn client (iperf client)

 

  1. When SSL VPN tunnel mode is set up, the iPerf testing result of FortiGate-61E is around 80Mbps.

 

截圖 2022-07-07 上午10.07.31.png

  1. Even if two SSL-VPN client are setup to generate two SSL-VPN tunnel traffic, the total bandwidth is around 90Mbps.

  

截圖 2022-07-07 上午10.12.13.png

  1. # diag sys top shows only one sslvpnd process serving the SSL-VPN tunnel traffic.

 

截圖 2022-07-07 上午10.11.51.png
Scope Version 6.4.9.
Solution
  1. Increase the sslvpnd worker account:

 

config system global
       set sslvpn-max-worker-count 2
end

 

  1. After the settings, when two SSL VPN client are setup to generate two SSL VPN tunnel traffic, the total bandwidth is around 150Mbps.

 

截圖 2022-07-07 上午10.23.41.png

  1. There are two sslvpnd processes serving the SSL-VPN tunnel traffic and increasing the bandwidth.

 

截圖 2022-07-07 上午10.23.19.png

Related articles: