We have fortigate 300E ( india office) & 100D (US office) both are connected via IPSEC tunnel. Link speed US office 10 Mbps down / 3 mbps UP Link speed India office 20 mbps down / 8 mbps now issue is on IPSEC tunnel when i copy file from India office to US office it give me speed around 1 Mbps But in reverse it gave only 100-120 kbps On SSL-VPN tunnel its even worse when i copy file from SSL-client to US office it give me speed around 800 kbps But in reverse it gave only 30-50 kbps max can anyone suggest me something how can i increase the speed of data transfer from US to india or US to SSL use Thanks in advance
[size="1"] FGT100E,FGT100D,FGT300C,FGT300E[/size] FortiOS 5.2, 5.4, 5.6,6.0,6.0.2 and 6.2
Solved! Go to Solution.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
How are you evaluating the transfer speeds? If this is a CIFS/SMB transfer the rate is showing in MB (Megabytes/sec) while you WAN connectivity is in Mb (Megabits/sec) I 1MB transfer on a 8Mb connection would be expected.
For throughput testing the Fortigate has a built in iperf "client" diagnose traffictest. iperf is a great way to test your connections capabilities.
In regards to IPSEC vs SSL VPN, in older versions of firmware SSL VPN used tcp which was much slower, however 5.4 and newer use udp which should have similar performance to IPSEC.
What OS version of firmware are running on both fgts? How are the file coping being performed? SMB? Has the MTU values be set (or need to be set) accordingly?
NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C
How are you evaluating the transfer speeds? If this is a CIFS/SMB transfer the rate is showing in MB (Megabytes/sec) while you WAN connectivity is in Mb (Megabits/sec) I 1MB transfer on a 8Mb connection would be expected.
For throughput testing the Fortigate has a built in iperf "client" diagnose traffictest. iperf is a great way to test your connections capabilities.
In regards to IPSEC vs SSL VPN, in older versions of firmware SSL VPN used tcp which was much slower, however 5.4 and newer use udp which should have similar performance to IPSEC.
india has 6.0.4 , US Has 6.0.2 firmware its using SMB
[size="1"] FGT100E,FGT100D,FGT300C,FGT300E[/size] FortiOS 5.2, 5.4, 5.6,6.0,6.0.2 and 6.2
update both to 6.0.6 and test again.
only solution i got for now that i created one IPSec tunnel for remote user using VPN wizard now connection speed little improved but the now am having other issue we have one website that is accessible from our network only which was working fine when connected to SSL but with IPSec remote VPN its not working Note: i have created same policy as we had for ssl vpn to access that website. let me know if any solution over this Thanks in Advance
[size="1"] FGT100E,FGT100D,FGT300C,FGT300E[/size] FortiOS 5.2, 5.4, 5.6,6.0,6.0.2 and 6.2
correct the policy for access the website and put right ip-network in it (the source ip net from the vpn-tunnel)...
hi Zaphod, thanks for quick reply. i did have put the right ip range address with that IPsec user getting connected to local network everthing is working fine the are able to access local network only thing is that traffic is not going to the new policy that i have created for that website for ipsec users. PFA for reference for policy both IPsec & SSL.
[size="1"] FGT100E,FGT100D,FGT300C,FGT300E[/size] FortiOS 5.2, 5.4, 5.6,6.0,6.0.2 and 6.2
- check the phase 2 definition for the ipsec-tunnel, is traffic to external site allowed in phase2?
- the policy is wrong if you use ipsec-tunnel...
Hi zaphod, I have allowed that particular website on in Phase 2 of Ipsec tunnel( please note this is remote Ipsec VPN for single user work with forticlient) please guide me about proper policy for the same
[size="1"] FGT100E,FGT100D,FGT300C,FGT300E[/size] FortiOS 5.2, 5.4, 5.6,6.0,6.0.2 and 6.2
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1641 | |
1069 | |
751 | |
443 | |
210 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.