Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
IronMan
New Contributor III

Help with configuring IPsec tunnel between 2 locations

I have firewalls in HQ and Branch. The goal is to send all traffic, internet and LAN from branch to HQ, so Branch will use the HQ internet. And HQ will have access to Branch LAN.

 

The branch has dynamic IP from the ISP and the ISP router handles PPPOE. So the firewall is connected behind the router, since the router handles VOIP lines as well. For now I'll leave it that way until I can test and confirm if IPsec is a suitable option for this project.

 

The tunnel is up and everything is working but my Branch internet download speed through the tunnel is 40Mbs which is acceptable since the HQ upload bandwidth is 50Mbs, but the Branch upload is only 8Mbs. This seems too low. Direct internet at the branch without tunnel is 100 down/50 up.

 

I have the tunnel set up as below. Please help me check if this optimal, or if anything is done incorrectly. I have two Phase2 selectors.

 

This is on HQ

Phase1

Transport: UDP

NAT traversal: Enable

DPD: On Demand

DPD retry count: 3

DPD retry interval: 10

Encryption: AES256-SHA256, Diffie H: 20

 

Phase2 A

Local address: 10.10.10.0/24

Remote address: 10.10.50.0/24

Phase2 B

Local address: 0.0.0.0/0

Remote address: 0.0.0.0/0

 

Static Route

Destination: 10.10.50.0/24 

Gateway: Branch IPsec tunnel

 

any idea or suggestions? let me know if more info is needed

2 REPLIES 2
AEK
SuperUser
SuperUser

Hello IronMan

Which FortiGate models, and which FortiOS versions?

Have you tried without using UTM in the related firewall rules?

AEK
AEK
IronMan
New Contributor III

Hi AEK

Fortigate 400E and 101F both version 7.6

No UTM on all policies for now. 

 

I adjusted the TCP MSM to 1360 and that brought the upload speed to 8Mbs as before that it was around 1.5Mbs

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors