Created on 09-18-2024 12:13 AM Edited on 01-21-2025 11:17 AM By amatos
Description | This article describes how to improve the speed performance when internet users access a Protected SSL Server (located behind the FortiGate). |
Scope | FortiGate. |
Solution |
Tunning the FortiGate option 'tcp-window-type' under the 'config firewall profile-protocol-options' could help to get better performance. The option 'tcp-window-type' has different values that could be assigned as per the network, shown below:
config firewall profile-protocol-options set tcp-window-type ? end
The default value is 'auto-tuning'. The Admin can change it to 'dynamic' where the FortiGate will adjust the value of the TCP window based on the FortiGate available memory and within the set values of tcp-window-minimum and tcp-window-maximum as below:
config firewall profile-protocol-options
Note: These two settings are not visible as long as the 'tcp-window-type' option is set to 'auto-tuning'. The admin can set the profile-protocol-options to include additional ports for the HTTP profile besides port 80, like port 443, as below:
config firewall profile-protocol-options |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.