Good day,
I am using the SSL VPN on my FortiGate FGT200F in full tunnel mode and after upgrading to the latest version of the firmware "7.v7.4.3 build2573 (Feature)" the VPN speed has been very slow and think this may be the cause.
I have been in contact with FortiGate support and they have said to try tweaking the MTU on my internet facing interfaces.
I don't really want to do this as will affect all traffic going through and not sure what systems it will affect, I have looked at my Firewall Profiles for the VPN IN & Out and can see the two settings below.
set tcp-mss-sender 0
set tcp-mss-receiver 0
Are these the setting I should change and not the interface MTU?
I have done a ping test for MTU and it come out at 1472 + 28 bytes = a MTU of 1500
The MSS values I think should be MTU - 40 bytes = a MSS of 1460
https://community.fortinet.com/t5/FortiGate/Technical-Tip-Setting-TCP-MSS-value/ta-p/194518
I am not an expert on this so can anyone give me some guidance on if what I am doing is correct.
Below is my speed test, don't understand why upload is fast and download is so slow.
Thanks
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hi,
- You can try to use dtls which will have better performance.
- MSS Setting will have impact on the TCP packets only. It reduces the segment size which essentially reduces the total size of the packet.
- I would not suggest to use the value "zero" in the configuration. You can try to change the value to 1400 and verify if it improves the performance. MSS value change will not have any impact if the communication is over udp.
Regards,
Shiva
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1679 | |
1085 | |
752 | |
446 | |
226 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.