Fortigate 100D to 100E on fiber site A 150/150 to fiber Site B 250/250.
I transfert from site B to site A on FTP 145mbits outside the VPN and 10 mbits on the same servers through the the vpn.
I have the same performance through vpnssl from my home (10mbits)
On ftp from my home 145mbits on site A and 230 from site B
I reach almost the speed of the fibe outside the vpn
Cpu's work at 5-10 %
Same result with 5.4.4 and now 5.6.2....
Enabling or disabling DTLS change nothing
config vpn ssl settings set dtls-tunnel enable/disable end
Ideas?
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hi there!
maybe a dumb question, but you have a traffic shaper or any UTM feature applied on any policies?
The transfer protocol is always FTP?
The IPSEC Tunnel is an interface mode tunnel?
no raffic shaper no UTM
All transnfert is slow... ftp, smb...
yes interface, he last test we created with the vpn wizard both side...
According datasheet, the IPSec VPNThoughput of each are:
Fortigate 100D: 380 Mbps
Fortigate 100E: 4 Gbps
So, this should work fine.
Can you disable the acceleration?
Maybe de SOC or the NPU are the issue.
If this not solved the problem, you've got to do some troublehooting, like check error logs, discarded packets or debug vpn traffic to obtain more data.
Hi,
last time I had really slow SMB traffic over ipsec using a 100D, the support told me to disable asic and hmac offloading for ipsec:
config sys global set ipsec hmac disable set ipsec asic disable end
This "fixed" it for me, the traffic is now 6 times faster than before.
Regards
bommi
NSE 4/5/7
Hi bommi,
In the example above, did you mean to have "set ipsec asic enable" or should it have been "disable"?
Also, what FortiOS version were you on when turning these off increased your SMB traffic speed?
I'm in the middle of setting up automatic archives that will go over IPsec to an offsite 100D on 5.4.6 but haven't seen speed issues yet.
Hi tanr,
yes it should be "disable" for both values, I changed it in my post above.
I had an extreme performance drop between an 100D and a 30E when using the asic for ipsec on the 100D.
We observed this on 5.6.2.
Regards
bommi
NSE 4/5/7
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1732 | |
1106 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.