Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
rohitchoudhary1978
New Contributor III

FortiClient IPsecVPN Issue: Inability to browse asterisk-based VoIP web application via HTTPS

Dear Team,
This email seeks assistance with a recurring issue experienced by field users attempting to access our internal asterisk-based VoIP web application, located at https://aaa.bbcone.com, through a FortiClient IPsec VPN tunnel.
While the application functions flawlessly when users connect via FortiClient SSL VPN, Now we are planning to shift all users to IPSec VPN. A subset of users connecting through IPsec VPN are encountering browsing difficulties. These users are able to successfully ping and telnet the application's domain/IP address, confirming network connectivity at a basic level. However, their web browsers are unable to establish a connection to the web application itself.
 
Initial troubleshooting included manually adding an entry to the hosts file on the affected Windows 11 workstations, which resolved the issue for some users. However, a significant number of Windows 11 users continue to experience the problem, indicating a deeper underlying issue.
Based on research, the potential cause of this browsing problem, despite successful ping, may be related to Maximum Transmission Unit (MTU) and/or TCP Maximum Segment Size (MSS) settings. We understand that incorrect MTU and MSS values can lead to packet fragmentation, which negatively impacts TCP-based communication like web browsing, especially when traversing a VPN tunnel due to added encapsulation headers. While we acknowledge the need to potentially adjust these values, we require clarification on the correct location to implement these adjustments within our Fortinet environment:
  • Should the MTU and/or TCP MSS be adjusted on the WAN interface of the FortiGate firewall, impacting all traffic traversing that interface?
  • Alternatively, should the adjustments be made specifically for traffic related to the web application (e.g., within firewall policies or virtual IPs)?
  • Or should these parameters be configured directly on the IPsec VPN tunnel interface itself, affecting only traffic encapsulated within the VPN?
Your expertise in guiding us through the appropriate configuration adjustments for MTU and TCP MSS to resolve this IPsec VPN browsing issue on Windows 11 clients for our asterisk-based VoIP web application would be greatly appreciated.
Thank you,
Rohit Kumar
Rohit K
Rohit K
1 REPLY 1
Igneus
New Contributor II

Hi,

I’ve seen similar behavior when configuring HTTPS/HTTP access to network devices (like switches or VoIP servers). Sometimes, in addition to MTU/MSS issues, the device itself requires that the client IP addresses be explicitly allowed (a kind of whitelist or management access ACL). So it’s worth double-checking that the asterisk-based server has your FortiClient IPsec VPN subnets permitted for web/management access.

give it a shot
give it a shot
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors