Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
RolandBaumgaertner72
Contributor III

Slow Connection between offices in Europe and US

Hi,

 

since this connection is new for us we dont have a lot of experience. The headquarter is in EU with 200F 7.4.5 and the new office is in the US 100F 7.4.5. Users are working with IPSec between the FGs and working on File Servers. In the HQ we use dedicated 1/1GB access for this VPN and in the US we have 1/1GB for all traffic for this >30 users.

 

First thing, one week they dont complain at all, than another week all users complain every day. Checking our internet access we never find a problem. There it is more complicated since there is no technician but doing speedtest on pages in Europe he downloads test files with 1GB almost as fast as we do here. When it is getting really bad, they say e.g that working on a Terminal Server in our HG the mouse moves really, really slow.

 

Than we started doing testing with iperf and with VIPs on both sides to the iperf server. We tried also from other FGs in Europe to our HQ and we got always > 300-500mb to this iperf server behind this 1/1GB line.

 

Doing the same from Europe to the FG in US we got max. 10-20mb. Even though when we started checking this situation copying large files we always got like (upload and download rates) 25-30mb/s which we thought are really good considering IPSec and latency of 120ms.

 

Of course we talked to the IPS and he told us when they did testing that the access is working just fine. Now we think of getting another access just for the VPN conncetion.

 

Any ideas or suggestions what we could check or do?

 

Thanks!

 

 

 

 

 

 

2 REPLIES 2
Anthony_E
Community Manager
Community Manager

Hello Roland,


Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.


Thanks,

Anthony-Fortinet Community Team.
Toshi_Esumi
SuperUser
SuperUser

First thing I would do is to make sure you get a proper number when you run speed test on US side by picking a local server since you didn't seem to have done yet.
Then the second thing I would do is to run traceroute from one side to the other for both directions so see if it's relatively symmetrical for in-between internet network providers after leaving your ISPs. And more importantly if the paths change often, especially when it's fine and when it's bad.
Once got some rough idea who you're connection is going through, I would measure the path MTU by pinging the other end with DF bit on to see if somebody inbetween has much smaller MTU inside their network.The numbers maybe different per direction. Once got the numbers, you can try adjusting either MSS (for TCP only) or interface MTU, to see if it would mitigate the slowdown.

Toshi

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors