Hi folks,
I have a FGR-60D running FOS 5.4 connected on a 100Mbps internet symetric fiber link. My objective is use it to create a dialup IPSec VPN for about 50 users connected with native Windows and native Android VPN clients.
My question:
On lab tests, connecting a VPN client trough a 1Gbps switch link (no internet) and trying to download a file from FTP server, I had only 70Mbps with 100% CPU (impossible to manage).
I supose that this high CPU load is quite abnormal, and could be caused by something related on lack of hardware accelerating.
I read a lot about NPU and hardware acceleration, but I did not realize if I can use NPU offloading on a dialup VPN (with native client) or just on a site-to-site VPN, or at least using FortiClient VPN software;
Have I missed something? Any suggestions?
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
One thing I could suggest is testing the test environment first without VPN just routing through but includes all component you used to test VPN. Since it's LAB environment you should be able to do it. Does it show much better number? Like 800Mbps?
You are damn right!!
First I connected two lab computers on port1 and port2 of internal switch of FGR60D [strike]and did achieve the same 70Mbps as I had with VPN, but with low CPU consumption.[/strike]
EDIT: My bad, I had connected trough a 100Mbps switch ... connecting directly to port1 and port2 they reached 1Gbps downloading from FTP, without VPN.
Then I connected the same computers on a gigabit switch and did achive 1Gbps.
[strike]So, it suggests something on Fortigate internal switch, that already is a Hardware Switch interface type.[/strike]
Many thanks
Summary: I did the tests again and I did reach 1Gbps on internal to internal, 1 Gbps routing internal to wan and 70Mbps on VPN. Unfortunately I still have high CPU usage on VPN, I had to apply a traffic shaper on VPN to limit it to 30Mbps, otherwise I couldn't manage the unit or even navigate on internet during a file transfer.
I'd like to have a throughput near to datasheet specs of IPSec 1Gbps, but the main issue now is the CPU usage that make the FGR unusable.
Is there anything else I have to check?
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1713 | |
1093 | |
752 | |
447 | |
231 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.