Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
IT_Admin83
New Contributor

Slow or no access to the web interface via VPN

Hello dear community,

A brief introduction since I’m new here.
I am an IT employee at a company, and over the years, we have been using a Sophos firewall. However, we are now switching all our branch offices to Fortinet.
I also successfully completed the FortiGate Administrator training at the beginning of this transition.

We started with our smallest branch and implemented the simplest rule set. So far, everything seems to work well—we have configured an IPsec VPN connection to our headquarters. At the headquarters, we still have a Sophos UTM 230 SG running. The VPN tunnel is established, and the ping is clean and fast at approximately 30 ms with a TTL of 254.

Our issue is that accessing the web interface over the VPN tunnel is nearly impossible. The login still works, but then a white page appears. If you’re lucky, content might load after a while. However, if you click on a menu item, the web interface freezes again.

At the branch office, we have a FortiGate 60F. The system load is low.
When accessing the web interface locally at the branch office, it works without any issues. So, the problem must be related to the VPN tunnel.
The MTU was set to 1500 on both sides. We tried lowering it to 1432 at the branch office, but it didn’t solve the issue.

The FortiGate at the branch office is connected through a Lancom router. This Lancom router forwards all ports directly to the FortiGate (Exposed Host).

At the moment, I’m unsure where to look for the source of the problem. Perhaps someone can give me a tip.

I hope I haven’t left out any important information. I can also upload log files if needed.

Thank you in advance and best regards!

2 REPLIES 2
ebilcari
Staff
Staff

Welcome to the Community!

What type of VPN is configured, is NAT involved, Dialup VPN? What is the MTU allowed by the Lancom router (you can test with DF ICMP packets)? 

Which IP interface of the branch FGT do you use to access its GUI remotely?

You can also refer to this article for more information related to MTU.

- Emirjon
If you have found a solution, please like and accept it to make it easily accessible for others.
IT_Admin83
New Contributor

Hello everyone,

First of all, thank you for your responses.
Apologies for the delayed reply, but I wasn’t able to get to it earlier.

I’ve managed to gather a bit more information. The issue seems to be related to the MTU size.
As mentioned before, we have an MTU of 1500 set on the Sophos side. We then set the Fortigate side to 1500 as well, and the performance improved significantly.
However, with an MTU of 1500 on the Fortigate side, we encountered a new problem: the antivirus scanner stopped updating through the cloud platform.
So, we reverted the MTU back to 1432, which allowed the antivirus scanner to function properly again, but the performance deteriorated.

The curious part is that we now have a second location with a fiber optic connection, and at that location, access to the web interface works perfectly with an MTU of 1432.
The location experiencing the performance issues is connected via VDSL with a copper line (100 Mbps down – 40 Mbps up).
Both locations are configured with the same VPN settings (Site-to-Site – IPsec).

Can anyone explain this? Should we experiment with the MTU size, for example, setting it to 1460?
With an MTU size of 1492, the performance was also poor, and the antivirus scanner didn’t update either.

Thank you for your support.

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors