Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
rfs3pa
New Contributor II

T-Mobile IPsec Trouble

I have a FortGate 61F running 7.4.6 in my main office behind cable internet with a static IP.

 

I have a remote office with a 40F running 7.4.5 behind a T-Mobile internet gateway.  It was the T-Mobile FAST 5688W and we a dial-up IPsec tunnel and it worked fine.

The site got a new T-Mobile TMO-G4SE gateway and now we have issues.  The FortiGates on both ends show the tunnel as Up and I can ping from each side from the other (about 130ms).  From the main office I can bring up the admin page for the remote FortiGate in a browser, but it is very slow.  Speed test on the remote side shows 250 Mbps or better.  Other web pages on the main office will not load on the remote side, and the remote side cannot connect to remote desktop hosted at the main side.

 

Any suggestions on what I should look at?  Thanks.

2 REPLIES 2
Atul_S
Staff & Editor
Staff & Editor

Hi There,

 

Pls validate your findings by doing a simple file transfer between the sites and note the values to determine the slowness. Since you are experiencing multiple flavours of problems, including slowness and no connectivity, you can aim at both problems. Assuming no changes were made to the Fortigate and everything was working fine prior to the change of ISP connection,  you can run the below debugs to determine the root cause. For example, for RDP not working, run a sniffer and debug on both sides of the Fortigate to determine the pain point. You can refer to the below doc for this(adjust the Ip add and port numbers accordingly):

https://community.fortinet.com/t5/FortiGate/Troubleshooting-Tip-First-steps-to-troubleshoot-connecti...

 

For Slowness, refer to the below doc:

https://community.fortinet.com/t5/FortiGate/Technical-Tip-Setting-TCP-MSS-value/ta-p/194518

 

It would be best, if you lodge a case with the TAC support. 

 

Thanks,

Atul Srivastava
Toshi_Esumi
SuperUser
SuperUser

I would suggest you sniff packets especially on the remote 40F on the wan interface/interface to the T-Mo device if you see "fragmented" in the flow of packets. If that's the case, you can adjust MTU side on the interface after measuring the real MTU on the path between two FGTs by pinging with DF bit on.
TCP MSS adjustment @Atul_S suggested is effective. But works only for TCP traffic, which wouldn't work for applications that mainly use UDP.

We had a similar issue with SSL VPN from a PC or Linux behind T-Mo device. But I gave up because the person who was complaining about was not so cable changing those parameters on his machine.
If FGT, and you have control of its config, much easier.

Toshi

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors