- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Internet Speed Problems between MPLS Interface and Azure IPSec
Hello,
we are working on this problem for some time now and we dont quite understand the problem.
We have FGs in smaller offices with MPLS connected to our mail firewall in a DC. We are using VMs in our local DC connected with MPLS (biggest ISP in the country) and also now some VMs in Azure connected via main Fortigate in DC and Fortigate in Azure Cloud (internet speed 200/200mb)
The problem is that users in branch offices which are working with a VM file server in Azure via SMB are reporting problems because of low performance. The ERP system has to save some files on the Azure VM and it takes a very long time. Uploadig files (later we checked with a big ISO file) we get like maximum 5-10mbits to Azure. For the IPsec to Azure we use our dedicated WAN with 1GB and have like 200mb on the Azure site.
So we started testing and checking the performance on all sides. From branches we have MPLS 1 GB (divided por streams so we are not 100% sure) to our DC. Downloading and uploading tests give us like 20-30mbits so we think this is OK considering the total of 1GB (maybe 600 for connection to our network). We doubled checked with iperf and so we got always like 250-350mb.
Testing directly from on of the VMs in our DC to Azure via IPSec doing the same up and download tests we get like 35-40mbits which is also OK.
So why are we loosing so much speed doing the same from the branches. They enter first the DC and main FGs with MPLS on the MPLS ALL Interface of the FGs and than from dedicated WAN via IPSec to Azure.
Any suggestions?
Thanks,
R
- Labels:
-
FortiGate
