Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Krissie
New Contributor

IPSec issue between 2 FortiGates

I have an issue that I would like some advice for. I have 2 sites with Fortigate 40F's and both sites are on a Comcast 1.25 Gpbs x 300 Mpbs circuit.

I have built an IPSec between sites and initially it seemed that the speeds were around 40 Mb (measured using iPerf) but they consistently keep dropping to unworkable speeds of less than 1 Mb. Comcast uses some product called "Security Edge" but I have turned it off on both sites. 

I am trying to work with Comcast to troubleshoot this issue but as expected, the service desk does not really seem to understand what a site to site is.. and speedtests on the network and connected devices and raw speed tests show proper speeds so Comcast blames the issue on the Fortigates and a misconfig on our end. The tunnels are super simple, Ike 2, aes and sha 256 and diffie 14. No inspection or any other things that could slow the tunnel down. 

Does anyone have an idea as to what could be causing this or what we can do to solve this issue? I don't even know what speeds we can realistically expect but obviously under 1 Mb is unworkable. Thanks for any help!

1 REPLY 1
funkylicious
SuperUser
SuperUser

"jack of all trades, master of none"
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors