Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
1mm
Contributor

Fortigate IPSec traffic issue

Hello,

 

We have 2 virtual fortigates - one is deployed in Azure environment, second in our local datacenter on ESXi infrastructure. On these 2 fortigates we have installed trial licenses (provided by vendor). We have configured IPsec over GRE between these 2 fortigates. Connection is stable but speed is very low, maximum in peak was 15 mbp\s. Not sure there is the problem..

5 REPLIES 5
spoojary
Staff
Staff
xshkurti
Staff
Staff

@1mm  try to force nat-t under ipsec phase1 config
Technical Tip: IPSec VPN nattraversal - Fortinet Community

v_ceban
Staff
Staff

I would suggest setting up a lower TCP-MSS ~ 1350 for both directions .
This is recommended for IPsec tunnels on FGTs hosted in Azure Cloud

https://docs.fortinet.com/document/fortigate/6.2.15/cookbook/255100/ipsec-vpn-to-azure-with-virtual-...
https://community.fortinet.com/t5/FortiGate/Technical-Tip-Setting-TCP-MSS-value/ta-p/194518

 

Vladislav Ceban
1mm
Contributor

Thanks for your replies,

I have one question, can it be referred to trial license? Are there any limitation of trial licenses provided by vendor?

maulishshah

@1mm , Based on my knowledge, we do not impose any resource limitations for trial licenses.

Maulish Shah
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors