Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Niall_Kelly
New Contributor

Slow Throughput over IPSEC VPN

Hello, We are using 2 X Fortigate 310 B V4.0 MR1 in a site to site /point to point configuration. We have a IPSec VPN between both devices but we are gettting a very poor throughput speed between both devices over the vpn. The point to point connection speed is 1 Gb but we are only achieving a max speed of 300 mbs. If we avoid going over the vpn and dont send traffic encrypted we get 900 mbs. We have tricked around with encryption settings to no avail. Does anyone have a similare issue? Regards, Niall
11 REPLIES 11
Niall_Kelly

Thanks Guys, So do I not need to follow the scenario guidlelines..ie....for a policy based IPsec do the following? Accelerated policy-based VPN configuration To configure FortiGate_1 1. Go to VPN > IPsec > Auto Key (IKE) and select Create Phase 1. 2. Configure Phase 1 settings (name FGT_1_IPsec), plus • Select Advanced. • Ensure that the Enable IPsec Interface Mode check box is not selected. • In Local Gateway IP, select Specify and enter the VPN IP address 3.3.3.1, which is the IP address of FortiGate_1’s FortiGate-ASM-FB4 module on port 2. 3. Select OK. 4. Select Create Phase 2 and configure Phase 2 settings, including • Select Enable replay detection. • set enc-offload-antireplay to enable using the config system npu CLI command. 5. Go to Policy > Policy > Policy. 6. Configure an IPsec VPN policy to apply the Phase 1 IPsec tunnel you configured in step 2 to traffic between FortiGate-ASM-FB4 module ports 1 and 2.
romanr
Valued Contributor

Hi, I don' t know wheter you use Tunnel or Policy mode vpn. In both offloading should be possible. You need to have - the local-gw parameter in the phase1 config config set to the local ip of your interface terminating this tunnel - this interface needs to be either a port on the NP2 or a vlan interface on one of the NP2 ports or lacp trunks there! - the " config system npu" parameters properly set as mentioned in the hardware manual - your encryption parameters must be offloadable - as stated in hardware manual. Everything else is same with any tunnel.... To see if your tunnel is offloaded use the following diag command: diagnose vpn tunnel list An offloaded tunnel will have an additional line on the bottom like this: npu_flag=03 npu_rgwy=XX.XX.XX.XX npu_lgwy=YY.YY.YY.YY npu_selid=3, dec:pkts/bytes=10625/5965258, enc:pkts/bytes=18860/3877627 br, Roman
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors