Hello :)
We have a fortigate 90D running multiple IPSEC vpns. One link is a little slow and keeps causing AS400 (IBM) sessions to drop.
As this uses telnet, how can I prioritise telnet packets through this VPN ?
Thanks
Tracy
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
As far my understanding there could be many reasons for the slowness over IPsec VPN.
[ul]And if you are using an interface based VPN create a seperate policy only with the Telnet service with " Traffic Shaping " options. And put the normal access policies below on that. So atleast you can ensure your telnet traffic is not stuck on traffic queue and it will have priority.
But Still I don't think that it will help you to fix the slowness issue unless you find out the root cause for the slowness issue. :)
I have to agree with nihas, and would even add have you ran any L4 analysis between client and AS400? A opensource tool like tcptrace will provide details on tx/rc retrans, delay,etc.....
www.tcptrace.org/
Once you have any ideal of the traffic statistics, than you can drill in. Also keep in mind you mem=ntion prioritizing telnet over ipsec but how much ipsec do you have at either vrs the available bandwdidth?
I would start by graphing the ipsec tunnels ( hopefully they are ALL interface mode ) and try to look at the available bandwidth and utilization at each ends.
PCNSE
NSE
StrongSwan
Hi guys,
maybe I am out of the thread, but could you explain how our FG unit can forward SNA traffic (AS400) in NAT/Route mode?
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1670 | |
1082 | |
752 | |
446 | |
226 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.