I am need of some help, we have a Fortigate 401f that is being utilized for internet off load.
RFC19818 to NON-RFC1918 go out the local internet pipe.
Rubrik support tunnel requires https/443 access to establish a connection to their proxy.rubrik.com site.
I have created a firewall rule to all my Rubrik Nodes access to ANY with ANY services allowed with AV, APP, IPS and SSL inspection enabled.
We have asymroute enabled.
On the pcaps, I am seeing a lot of retransmits and I am wondering if this is a possible mtu or mss size issue, but I am not sure how to find that or determine that information from the pcaps.
I think this issue is also causing the same problem with another app that keeps timing out and on it I see retransmissions and a lot of client-rst.
I would I go about detemining the correct mtu/mss size for these applications and I would I make these changes per the policy.
Thanks,
it is a 401f ---> Cisco 2960x ---> ISP
The cisco 2960x is utilized as a later 2 switch.
Use Wireshark or other packet capture tools to analyze the PCAPs. Calculate the optimal MSS size based on the MTU of the path minus the IP and TCP headers.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1737 | |
1108 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.