We have a Fortigate 200 between our LAN and a 15Mb internet connection. At an offsite location, we have a 6Mb circuit. Using a laptop and Forticlient at the offsite location, we are unable to get more than 1.95Mb/s through the VPN with FTP transfers. (and only 750Kbps with Windows file copy).
When not using the VPN, each site can get 4Mb/s+ , as tested through large file transfers and bandwidth testing websites. We are not maxing out the bandwidth at either site, so traffic shaping is not in play.
Fortigate Technicians have told us everything from " enable traffic shaping" to " each policy must have a priority" . We have tried traffic shaping with what little documentation is available, but it made no difference in throughput. (if you know of any traffic shaping documentation, that would be appreciated too)
We have no trouble connecting to the VPN, and no trouble maintaining the connection. Pings are 30ms or better. Fortigate CPU util hasn' t gone over 20% and memory usage doesnt exceed 50% during our tests.
I realize IPSec has some overhead associated with it, but I wouldn' t figure it would be that much. With plans to use a Fortigate60-Fortigate200 hardware VPN between these sites, I would like to be sure this isn' t going to be an issue.
If anyone has had any experience solving this type of issue, I would appreciate your input.
Thanks!