Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
pegasokra
New Contributor

Delay in accessing the network after connecting to SSL VPN + ZTNA

Hello,

 

I'm facing a problem, I have a FortiEMS delivering ZTNA TAGS to my users with FortiClient with telemetry.

 

What happens is that every time users access the SSL VPN they have to wait seconds or minutes to access its resources, it's like there's a delay.

 

Firewall policies have ZTNA tags to allow communication.

 

This is normal? If so, is there a way to bypass this delay somehow, or configure it so it doesn't occur?

10.0.0.0.1 192.168.1.254
3 REPLIES 3
AEK
SuperUser
SuperUser

Hello

Try check in firewalls traffic log why the packets are blocked during the first minutes.

AEK
AEK
msolanki
Staff
Staff

IS the resources access via https proxy ? if its simple sslvpn then you can enable DTLS on FCT and SSL VPN setting on FortiGate also check the MTU size in policy

mpeddalla
Staff
Staff

Hello @pegasokra  ,

 

Thank you for contacting the Fortinet Forum portal.

 

-I would recommend verifying if the firewall policy is flow-based or proxy-based along with any inspections enabled on the firewall policy.

-Does it affect all users or specific user?

-Is there any particular time in the day or week they reported or all the time?

-Can you confirm the firmware version of fortiEMS and Forticlient you are using along with FortiGate?

-Please make sure DTLS is enabled on Forticlient along with Fortigate

https://community.fortinet.com/t5/FortiGate/Technical-Tip-Using-DTLS-to-improve-SSL-VPN-performance/...

-Have you done any recent upgrades or changes on configurations?

 

Best regards,

Manasa.

 

If you feel the above steps helped to resolve the issue mark the reply as solved so that other customers can get it easily while searching on similar scenarios.

Labels
Top Kudoed Authors