Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
haiduongacm
New Contributor

Speed VPN Site to Site have problems ?

I have two line Internet from two site.

Site 1 : Speed 300Mbps, Fortinet 80D

Site 2 : Speed 250Mbps, Fortinet 140D

Case 1 : I connect VPN Ipsec or PPTP with 2 line by Router Draytek : Speed copy file together is 20MB/s to 25MB/s

Case 2 : I connect VPN Ipsec with 2 line by 80D and Draytek : Speed copy file together is 2MB/s to 9MB/s

Case 3 : I connect VPN Ipsec with 2 line by 140D and Draytek : Speed copy file together is 2MB/s to 9MB/s

Case 4 : I connect VPN Ipsec with 2 line by 80D and 140D : Speed copy file together is 2MB/s to 9MB/s

 

And why case 2 3 4 if using any router Fortinet speed very slow?

i try change another line internet, disable/enable DTLS but not working.

6 REPLIES 6
ede_pfau
SuperUser
SuperUser

Hi,

 

how do you connect the FGTs to the line - via modem? Which protocol do you use for the WAN access: PPPoE, DHCP, static line?

 

Ede Kernel panic: Aiee, killing interrupt handler!
Ede Kernel panic: Aiee, killing interrupt handler!
haiduongacm

Hi Ede

just one line interent via modem, and using PPPOE

ede_pfau

which device is doing the PPPoE - the FGT or the modem?

FGT have to handle PPPoE by CPU which limits throughput to ~130 Mbps on D series models. Haven't tested E series in this respect. Modems (Draytek et al.) handle the protocol in hardware so that they can reach near wirespeed.

Ede Kernel panic: Aiee, killing interrupt handler!
Ede Kernel panic: Aiee, killing interrupt handler!
haiduongacm

If FGT  handle PPPoE by CPU which limits throughput to ~130 Mbps on D series models, why internet speed is 300Mbps, it just slow with VPN ipsec site to site

ede_pfau

OK, that wasn't clear to me.

Low IPsec throughput is a rare condition IMHO. The 80D is rated at 200 Mbps, the 140D at 450 Mbps for IPsec traffic. It seems the traffic is not offloaded/accelerated. The 80D does not have an NPx network ASIC, neither the 140D. Yet, both should be able to sustain the rates given in the datasheets.

 

Of course, if the VPN is created between the 80D and the 140D, the FGT with the lower throughput will determine the overall throughput. This will likely be the 80D then.

 

Try to not set any protection profile in the policy involved.

Ede Kernel panic: Aiee, killing interrupt handler!
Ede Kernel panic: Aiee, killing interrupt handler!
haiduongacm

hi Ede

I don't set any protection profile in policy, if the FGT with the lower throughput will determine the overall throughput, 80D is rated 200Mbps i using 300Mbps internet, 140D using 250Mbps internet, i think speed VPN about 15-20MB/s

can i do anyway

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors