Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
RolandBaumgaertner72
Contributor

VPN Connection Europe to Brasil

Hi,

 

we have a FG200F on our main headquarter and a new office in Brasil with FG60F. We configured a VPN connection between the FGs (IKE V2, AES256-SHA256. AES256-SHA256). Both sides have 1GB internet access (well on the other side we are not so sure but some tests gave us very high bandwith).

 

Now the problem, users from Brasil connect to our office with RDP and sometimes they complain about preformance. So it is not everyday but sometimes they cant even refresh a RDP screen. We have like 195ms latency.

 

Has anyone experience and any ideas what we can do to check and improve?

 

Thanks 

5 REPLIES 5
msolanki
Staff
Staff

please tried to disable Anti-replay of phase-2 and check the RDP server setting too.

KB in sslvpn case but check setting for RDP server

https://community.fortinet.com/t5/FortiGate/Technical-Tip-Windows-RDP-connection-dropped/ta-p/197443...

RolandBaumgaertner72

Yes we can try that on one host but this is S2S IPSec, no SSL VPN.

 

Any ideas what could be done on the VPN parameters to gain stability? At the end checking the usage yesterday they only get 15MB according to the VPN bandwith wizzard.

 

Thanks

sjoshi
Staff
Staff

Hi,

 

Can you check by disabling NPU offload if that could be of any help

https://docs.fortinet.com/document/fortigate/7.6.0/hardware-acceleration/636026/disabling-np-offload...

 

Further please check the CPU/Memory status of the device too.

Let us know if this helps.
Salon Raj Joshi
RolandBaumgaertner72

Hi,

 

never done that, can we expect some change from that?

 

Checking CPU and Memory looks all good, we only have like max. 2000 sessions in 24h on the FG60F site. The other one is safe for sure since we also have other VPN connections that are working with no problems.

 

Thanks

sjoshi

yes npu you can try disabling it but do it in off hours because disabling/enabling NPU will flap the tunnel

You can also do the iperf test

https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-troubleshoot-speed-issue-through-IP...

Let us know if this helps.
Salon Raj Joshi
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors