Fortinet to Fortinet, 100E to 60E, IPSec Tunnel, gigabit connection on the 100E and 400mbit on the 60E.
SMB transfers are slow, about 2 or 3mbps.
Have adjusted tcp-mss in the IPV4 policy for the indicated branch and on the IPSEC interface itself to 1306 (which is low but higher doesn't matter, when left at default it was fragmenting so I lowered it)
config sys interface
edit <interfacename>
set tcp-mss 1306
end
AND
config firewall policy
edit <policy number>
set tcp-mss-sender 1306
set tcp-mss-receiver 1306
end
(configured both legs of the firewall policy, inbound and outbound, on both firewalls)
Perhaps of note, IPSEC tunnels to Juniper firewalls perform normally (also have tcp-mss set to 1306) . . .
What setting am I missing?
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Any help at all appreciated. I suspect the issue is that the tcp-mss setting isn't taking, but I simply can't find any other places I can set it.
Maybe related - see this post regarding disable asic and hmac offloading for ipsec.
config sys global set ipsec hmac disable set ipsec asic disable end
NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C
Thanks - has anyone done this? Does it interrupt service?
OK it does interrupt service but only for a second or so. Also, it doesn't have any effect. I in fact already had it set on both sides of one of the tunnels (from a 200E to a 100E). Still only getting about 8mbit/sec on gig links . . .
Any other possiblities?
Atsak, did you try latest IPS engine(interim one) where was made some SMB performace improvements?
Please rise a ticket with support in order to provide you the latest interim IPS engine.
BTW, which firmware is in problem?
IPS is disabled.
A ticket is open with Support, they have not replied (two days too better follow up)
Firmware is 5.6.3 build 1547 on both
Really important to note - the issue only exists between 60E and the datacenter 100E. IN offices where we have a Juniper, this doesn't happen, throughput is normal (maxes out CPU on the Juniper SSG 5's at around 40bmit). This makes me think its a PMTU or tcp-mss setting, but I don't know which one to toggle to fix it. This has to be a common problem I would think no?
If you find something please let me know as well. I've been looking for a long time and have come up empty handed. The one thing that has helped was enabling NAT on the tunnel but was barely noticeable. The command below was run on both ends (only effective if Fortinet to Fortinet)
config vpn ipsec phase1-interface
edit phase1name
set nattraversal forced
Hope this makes a difference for you.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1663 | |
1077 | |
752 | |
446 | |
220 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.