I have an issue that I would like some advice for. I have 2 sites with Fortigate 40F's and both sites are on a Comcast 1.25 Gpbs x 300 Mpbs circuit.
I have built an IPSec between sites and initially it seemed that the speeds were around 40 Mb (measured using iPerf) but they consistently keep dropping to unworkable speeds of less than 1 Mb. Comcast uses some product called "Security Edge" but I have turned it off on both sites.
I am trying to work with Comcast to troubleshoot this issue but as expected, the service desk does not really seem to understand what a site to site is.. and speedtests on the network and connected devices and raw speed tests show proper speeds so Comcast blames the issue on the Fortigates and a misconfig on our end. The tunnels are super simple, Ike 2, aes and sha 256 and diffie 14. No inspection or any other things that could slow the tunnel down.
Does anyone have an idea as to what could be causing this or what we can do to solve this issue? I don't even know what speeds we can realistically expect but obviously under 1 Mb is unworkable. Thanks for any help!
you could look at https://community.fortinet.com/t5/FortiGate/Technical-Tip-Ensuring-IPsec-traffic-is-offloaded-for-im...
User | Count |
---|---|
2642 | |
1405 | |
810 | |
685 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.