I have a FortGate 61F running 7.4.6 in my main office behind cable internet with a static IP.
I have a remote office with a 40F running 7.4.5 behind a T-Mobile internet gateway. It was the T-Mobile FAST 5688W and we a dial-up IPsec tunnel and it worked fine.
The site got a new T-Mobile TMO-G4SE gateway and now we have issues. The FortiGates on both ends show the tunnel as Up and I can ping from each side from the other (about 130ms). From the main office I can bring up the admin page for the remote FortiGate in a browser, but it is very slow. Speed test on the remote side shows 250 Mbps or better. Other web pages on the main office will not load on the remote side, and the remote side cannot connect to remote desktop hosted at the main side.
Any suggestions on what I should look at? Thanks.
Hi There,
Pls validate your findings by doing a simple file transfer between the sites and note the values to determine the slowness. Since you are experiencing multiple flavours of problems, including slowness and no connectivity, you can aim at both problems. Assuming no changes were made to the Fortigate and everything was working fine prior to the change of ISP connection, you can run the below debugs to determine the root cause. For example, for RDP not working, run a sniffer and debug on both sides of the Fortigate to determine the pain point. You can refer to the below doc for this(adjust the Ip add and port numbers accordingly):
https://community.fortinet.com/t5/FortiGate/Troubleshooting-Tip-First-steps-to-troubleshoot-connecti...
For Slowness, refer to the below doc:
https://community.fortinet.com/t5/FortiGate/Technical-Tip-Setting-TCP-MSS-value/ta-p/194518
It would be best, if you lodge a case with the TAC support.
Thanks,
I would suggest you sniff packets especially on the remote 40F on the wan interface/interface to the T-Mo device if you see "fragmented" in the flow of packets. If that's the case, you can adjust MTU side on the interface after measuring the real MTU on the path between two FGTs by pinging with DF bit on.
TCP MSS adjustment @Atul_S suggested is effective. But works only for TCP traffic, which wouldn't work for applications that mainly use UDP.
We had a similar issue with SSL VPN from a PC or Linux behind T-Mo device. But I gave up because the person who was complaining about was not so cable changing those parameters on his machine.
If FGT, and you have control of its config, much easier.
Toshi
User | Count |
---|---|
2571 | |
1364 | |
796 | |
651 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.