Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
john_barbour
New Contributor

Rubrik support Tunnel access not working

I am need of some help, we have a Fortigate 401f that is being utilized for internet off load. 

 

RFC19818 to NON-RFC1918 go out the local internet pipe. 

 

 

Rubrik support tunnel requires https/443 access to establish a connection to their proxy.rubrik.com site. 

I have created a firewall rule to all my Rubrik Nodes access to ANY with ANY services allowed with AV, APP, IPS and SSL inspection enabled. 

 

We have asymroute enabled. 

 

On the pcaps, I am seeing a lot of retransmits and I am wondering if this is a possible mtu or mss size issue, but I am not sure how to find that or determine that information from the pcaps. 

 

I think this issue is also causing the same problem with another app that keeps timing out and on it I see retransmissions and a lot of client-rst. 

 

I would I go about detemining the correct mtu/mss size for these applications and I would I make these changes per the policy. 

 

Thanks, 

3 REPLIES 3
hbac
Staff
Staff

Hi @john_barbour,

 

Can you provide a network diagram? Is asymroute really necessary? 

 

Regards, 

john_barbour

it is a 401f ---> Cisco 2960x ---> ISP 

The cisco 2960x is utilized as a later 2 switch. 

 

spoojary
Staff
Staff

Use Wireshark or other packet capture tools to analyze the PCAPs. Calculate the optimal MSS size based on the MTU of the path minus the IP and TCP headers.

 

https://community.fortinet.com/t5/FortiGate/Technical-Tip-ICMP-error-code-3-Fragmentation-Needed/ta-...

Siddhanth Poojary
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors