Dear Team,
This email seeks assistance with a recurring issue experienced by field users attempting to access our internal asterisk-based VoIP web application, located at
https://aaa.bbcone.com, through a FortiClient IPsec VPN tunnel.
While the application functions flawlessly when users connect via FortiClient SSL VPN, Now we are planning to shift all users to IPSec VPN. A subset of users connecting through IPsec VPN are encountering browsing difficulties. These users are able to successfully ping and telnet the application's domain/IP address, confirming network connectivity at a basic level. However, their web browsers are unable to establish a connection to the web application itself.
Initial troubleshooting included manually adding an entry to the hosts file on the affected Windows 11 workstations, which resolved the issue for some users. However, a significant number of Windows 11 users continue to experience the problem, indicating a deeper underlying issue.
Based on research, the potential cause of this browsing problem, despite successful ping, may be related to Maximum Transmission Unit (MTU) and/or TCP Maximum Segment Size (MSS) settings. We understand that incorrect MTU and MSS values can lead to packet fragmentation, which negatively impacts TCP-based communication like web browsing, especially when traversing a VPN tunnel due to added encapsulation headers. While we acknowledge the need to potentially adjust these values, we require clarification on the correct location to implement these adjustments within our Fortinet environment:
- Should the MTU and/or TCP MSS be adjusted on the WAN interface of the FortiGate firewall, impacting all traffic traversing that interface?
- Alternatively, should the adjustments be made specifically for traffic related to the web application (e.g., within firewall policies or virtual IPs)?
- Or should these parameters be configured directly on the IPsec VPN tunnel interface itself, affecting only traffic encapsulated within the VPN?
Your expertise in guiding us through the appropriate configuration adjustments for MTU and TCP MSS to resolve this IPsec VPN browsing issue on Windows 11 clients for our asterisk-based VoIP web application would be greatly appreciated.
Thank you,
Rohit Kumar
Rohit K