- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Slow Connection between offices in Europe and US
Hi,
since this connection is new for us we dont have a lot of experience. The headquarter is in EU with 200F 7.4.5 and the new office is in the US 100F 7.4.5. Users are working with IPSec between the FGs and working on File Servers. In the HQ we use dedicated 1/1GB access for this VPN and in the US we have 1/1GB for all traffic for this >30 users.
First thing, one week they dont complain at all, than another week all users complain every day. Checking our internet access we never find a problem. There it is more complicated since there is no technician but doing speedtest on pages in Europe he downloads test files with 1GB almost as fast as we do here. When it is getting really bad, they say e.g that working on a Terminal Server in our HG the mouse moves really, really slow.
Than we started doing testing with iperf and with VIPs on both sides to the iperf server. We tried also from other FGs in Europe to our HQ and we got always > 300-500mb to this iperf server behind this 1/1GB line.
Doing the same from Europe to the FG in US we got max. 10-20mb. Even though when we started checking this situation copying large files we always got like (upload and download rates) 25-30mb/s which we thought are really good considering IPSec and latency of 120ms.
Of course we talked to the IPS and he told us when they did testing that the access is working just fine. Now we think of getting another access just for the VPN conncetion.
Any ideas or suggestions what we could check or do?
Thanks!
- Labels:
-
FortiGate
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello Roland,
Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.
Thanks,
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
First thing I would do is to make sure you get a proper number when you run speed test on US side by picking a local server since you didn't seem to have done yet.
Then the second thing I would do is to run traceroute from one side to the other for both directions so see if it's relatively symmetrical for in-between internet network providers after leaving your ISPs. And more importantly if the paths change often, especially when it's fine and when it's bad.
Once got some rough idea who you're connection is going through, I would measure the path MTU by pinging the other end with DF bit on to see if somebody inbetween has much smaller MTU inside their network.The numbers maybe different per direction. Once got the numbers, you can try adjusting either MSS (for TCP only) or interface MTU, to see if it would mitigate the slowdown.
Toshi
