Hi,
we have a FG200F on our main headquarter and a new office in Brasil with FG60F. We configured a VPN connection between the FGs (IKE V2, AES256-SHA256. AES256-SHA256). Both sides have 1GB internet access (well on the other side we are not so sure but some tests gave us very high bandwith).
Now the problem, users from Brasil connect to our office with RDP and sometimes they complain about preformance. So it is not everyday but sometimes they cant even refresh a RDP screen. We have like 195ms latency.
Has anyone experience and any ideas what we can do to check and improve?
Thanks
please tried to disable Anti-replay of phase-2 and check the RDP server setting too.
KB in sslvpn case but check setting for RDP server
Yes we can try that on one host but this is S2S IPSec, no SSL VPN.
Any ideas what could be done on the VPN parameters to gain stability? At the end checking the usage yesterday they only get 15MB according to the VPN bandwith wizzard.
Thanks
Hi,
Can you check by disabling NPU offload if that could be of any help
Further please check the CPU/Memory status of the device too.
Hi,
never done that, can we expect some change from that?
Checking CPU and Memory looks all good, we only have like max. 2000 sessions in 24h on the FG60F site. The other one is safe for sure since we also have other VPN connections that are working with no problems.
Thanks
yes npu you can try disabling it but do it in off hours because disabling/enabling NPU will flap the tunnel
You can also do the iperf test
User | Count |
---|---|
2677 | |
1412 | |
810 | |
703 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.