Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
IPsec VPN speed issues.
Hello, we utilized IPsec VPN last month, and several of our remote users
are expressing concerns about sluggish internet speeds when they activate the VPN.
Certain users have had their connections reduced by 50%, while others have faced a decrease of 80%.
Kindly be aware that the remote server is located a significant distance from the remote users.
Is there something we can do to improve their speed?
Labels:
- Labels:
-
FortiClient
-
IPsec
2 REPLIES 2
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello AnonymusUser,
Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.
Thanks,
Jean-Philippe - Fortinet Community Team
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello again,
Can you check if these steps can help you, please?
- Enable IPsec Soft Dec Async:
- For FortiGate VMs in AWS, enable the `ipsec-soft-dec-async` setting to distribute and decrypt IPsec sessions using available VM cores.
- Configuration: `# config system global set ipsec-soft-dec-async enable end ` - Optimize Network Card Settings:
- Ensure the network card’s transmit queue (`txqueuelen`) is set appropriately.
- Check settings for TCP segmentation offload (TSO), generic segmentation offload (GSO), and checksum offloading. - Use AEAD algorithms like AES-GCM for encryption and integrity protection, as they are faster and supported by modern CPUs.
- Enable NPU Offload: If using FortiGate devices, ensure NPU offload is enabled to improve performance by offloading processing to network processors.
- Optimize Outbound Hashing: For FortiGate 3960E and 3980E, configure outbound hashing to distribute IPsec traffic efficiently among NP6 processors.
- Consider Internet Line Type: Use an Internet leased line instead of PPPoE for better support of NPU offload and improved performance.
Hope this will help you :)
Jean-Philippe - Fortinet Community Team
