hi,
i recently migrated from ASA to FGT and received complaints that HTTPS traffic is very "slow".
when i moved back to ASA, it works fine.
i suspect there's an issue in MTU or TCP MSS or both along the path.
1) can someone advise what is the "optimum" value for MTU and TCP MSS?
2) is there a way to know/test this from client machine?
3) should i set either one or both to 1400 or 1300 to avoid "slowness" issue?
config system interface
edit "wan"
set mtu-override enable <<< DO I NEED TO ADD THIS?
set mtu <MTU Value>
set tcp-mss <MSS Value>
next
edit "lan"
set mtu-override enable <<< DO I NEED TO ADD THIS?
set mtu <MTU Value>
set tcp-mss <MSS Value>
Hi johnlloyd13,
There are many differences between ASA and FortiGate. Could you please provide the following details to help us better understand your setup?
Regards
BIll
hi,
it's just a simple SNAT/PAT rule using the egress interface public IP.
the logs, session view looked "normal".
it was just slow web/HTTPS traffic browsing experience for the end users.
User | Count |
---|---|
2592 | |
1380 | |
800 | |
659 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.