Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Zero
New Contributor

Slow FortiClient VPN

Hello,

we are migrating from cisco AnyConnect VPN to FortiClient VPN. we are using FortiClient 7.2.5 and FortiGate 7.2.7 . we are seeing a significant difference in file transfer rate when the end user is trying to download a big file from a shared drive. I am pretty sure its not the internet circuit issue because I ran the test while I was working remotely. I have a 1Gb up/down and the download rate is similar to what our end-users are reporting. any help is greatly appreciated.

 

AnyConnectAnyConnectFortiClientFortiClient

Zer0o0o0o
Zer0o0o0o
9 REPLIES 9
homalgo1
New Contributor

Try the other way around, actually - disable split DNS, and let your internal DNS server handle all DNS for the client. (This assumes the internal DNS is willing and capable of resolving any public DNS records) https://mobdro.bio/

Zero
New Contributor

its already setup to use our internal DNS. split DNS already disabled

Zer0o0o0o
Zer0o0o0o
tpatel
Staff
Staff

Hello, 

Make sure dtls is enable in ssl vpn setting on fortigate and also on forticlient. 

Please click on below link and reference document.

https://community.fortinet.com/t5/FortiGate/Technical-Tip-Using-DTLS-to-improve-SSL-VPN-performance/...

Zero
New Contributor

enabled dtls in both the Fortigate and FortiClient but still the same max transfer rate is between 1MB/s - 3MB/s

Zer0o0o0o
Zer0o0o0o
tpatel

Hello, 
For testing can you try to disable all UTM profile in ssl vpn policy and make sure you are using flow based.

Check speed after that. 
If still you are getting same speed you need to setup iperf server on local environment and you need to check speed. 
https://community.fortinet.com/t5/Customer-Service/Technical-Tip-How-to-increase-the-SSL-VPN-tunnel-...

 

Zero
New Contributor

is this what you mean by disabling UTM? we already set our vpn policies for no-inspection.

VPN-FW-Policy.jpg

 

 

 

Zer0o0o0o
Zer0o0o0o
rahulkaushik-22

@Zero 

Create a VIP object and send the file over the Internet to check the speed difference when sent over the Internet vs SSLVPN.
https://community.fortinet.com/t5/FortiGate/Technical-Tip-Virtual-IP-VIP-port-forwarding-configurati...

Try to use latest version of Forticlient to rule out the Forticlient issue or try IPSec VPN rather than SSLVPN.







Regards, 
Rahul Kaushik

MR RAHUL K KAUSHIK
patelr
Staff
Staff

Hello @Zero 

 

Make sure, there isn't any VPN applications are installed, or running on test machine other than FortiClient .

 

Thanks, 
Ronak Patel

Zero
New Contributor

do you mean uninstall Cisco AnyConnect?.. its been off during testing FortiClient VPN.

Zer0o0o0o
Zer0o0o0o
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors