Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
1mm
Contributor

Fortigate IPSec traffic issue

Hello,

 

We have 2 virtual fortigates - one is deployed in Azure environment, second in our local datacenter on ESXi infrastructure. On these 2 fortigates we have installed trial licenses (provided by vendor). We have configured IPsec over GRE between these 2 fortigates. Connection is stable but speed is very low, maximum in peak was 15 mbp\s. Not sure there is the problem..

5 REPLIES 5
spoojary
Staff
Staff
xshkurti
Staff
Staff

@1mm  try to force nat-t under ipsec phase1 config
Technical Tip: IPSec VPN nattraversal - Fortinet Community

v_ceban
Staff
Staff

I would suggest setting up a lower TCP-MSS ~ 1350 for both directions .
This is recommended for IPsec tunnels on FGTs hosted in Azure Cloud

https://docs.fortinet.com/document/fortigate/6.2.15/cookbook/255100/ipsec-vpn-to-azure-with-virtual-...
https://community.fortinet.com/t5/FortiGate/Technical-Tip-Setting-TCP-MSS-value/ta-p/194518

 

Vladislav Ceban
1mm
Contributor

Thanks for your replies,

I have one question, can it be referred to trial license? Are there any limitation of trial licenses provided by vendor?

maulishshah

@1mm , Based on my knowledge, we do not impose any resource limitations for trial licenses.

Maulish Shah
Labels
Top Kudoed Authors