Created on
10-29-2019
01:43 AM
Edited on
02-03-2025
04:19 AM
By
Jean-Philippe_P
Description
This article describes the new option on FortiOS v6.2 that forwards Error Correction for IPsec VPN.
Forward Error Correction (FEC) is used to lower the packet loss ratio by consuming more bandwidth.
Scope
FortiGate.
Solution
Six new parameters are added to the IPsec phase1-interface settings:
fec-ingress: Enable/disable Forward Error Correction for ingress IPsec traffic (default = disable). fec-ingress waits for duplicate packets if the final packet is lost.
fec-egress: Enable/disable Forward Error Correction for egress IPsec traffic (default = disable). fec-engress sends duplicate packets.
fec-base: The number of base Forward Error Correction packets (1 - 100, default = 20).
fec-redundant: The number of redundant Forward Error Correction packets (1 - 100, default = 10).
fec-send-timeout: The time before sending Forward Error Correction packets, in milliseconds (1 - 1000, default = 8).
fec-receive-timeout: The time before dropping Forward Error Correction packets, in milliseconds (1 - 10000, default = 5000).
FEC is disabled by default. FortiGate supports unidirectional and bidirectional FEC and achieves the expected packet loss ratio and latency by tuning the above parameters.
Two checkboxes are added to the IPsec phase1 settings in the GUI:
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.