I have firewalls in HQ and Branch. The goal is to send all traffic, internet and LAN from branch to HQ, so Branch will use the HQ internet. And HQ will have access to Branch LAN.
The branch has dynamic IP from the ISP and the ISP router handles PPPOE. So the firewall is connected behind the router, since the router handles VOIP lines as well. For now I'll leave it that way until I can test and confirm if IPsec is a suitable option for this project.
The tunnel is up and everything is working but my Branch internet download speed through the tunnel is 40Mbs which is acceptable since the HQ upload bandwidth is 50Mbs, but the Branch upload is only 8Mbs. This seems too low. Direct internet at the branch without tunnel is 100 down/50 up.
I have the tunnel set up as below. Please help me check if this optimal, or if anything is done incorrectly. I have two Phase2 selectors.
This is on HQ
Phase1
Transport: UDP
NAT traversal: Enable
DPD: On Demand
DPD retry count: 3
DPD retry interval: 10
Encryption: AES256-SHA256, Diffie H: 20
Phase2 A
Local address: 10.10.10.0/24
Remote address: 10.10.50.0/24
Phase2 B
Local address: 0.0.0.0/0
Remote address: 0.0.0.0/0
Static Route
Destination: 10.10.50.0/24
Gateway: Branch IPsec tunnel
any idea or suggestions? let me know if more info is needed
Hello IronMan
Which FortiGate models, and which FortiOS versions?
Have you tried without using UTM in the related firewall rules?
Hi AEK
Fortigate 400E and 101F both version 7.6
No UTM on all policies for now.
I adjusted the TCP MSM to 1360 and that brought the upload speed to 8Mbs as before that it was around 1.5Mbs
User | Count |
---|---|
2554 | |
1356 | |
795 | |
647 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.