Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
wcbenyip
New Contributor III

VPN Connectivity with China offices

Hi, Does there anyone here has the experience to setup the vpn tunnel with remote offices in China? As we all know, the FG device support the FG gateway with DDNS; but I would like to know the performance between the vpn tunnels with DDNS, especially the connectivity with china offices... anyone could help? And, does there any ' limitation' for the Internet access and the vpn connectivity in china? Thx!!
Protect yourself~ http://www.secunia.com MBCS CEH FCNSA
Protect yourself~ http://www.secunia.com MBCS CEH FCNSA
5 REPLIES 5
Not applicable

Wow... this is a very late response. I have heard that an office in Beijing has a VPN between it and an office in Singapore. I have no idea what type of VPN it is or what crypto. level it is, but it might be possible. There are crypto. laws in many countries and laws pertaining to crypto. to other countries. -Jim
Not applicable

I guess probably, not only VPN connection, but the latency for the connection.. Have you tried to do a trace to their offices? My .2 cents..
wcbenyip
New Contributor III

Thanks jim and hugo, I have already tried the Forticlient with DDNS (via oray.org) in China to build up the VPN tunnel with HK Office, and the result is not quite stable... actually the problem seems caused from the DDNS provider... but oray.org is the biggest one in china, so I am not sure it' s the problem of the ADSL link or the DDNS provider - however, I have setup a DDNS name in oray.org and it' s really cannot get access to the server and update the latest dynamic IP address with the provider~ And now, I am setting up the FortiClient with 0.0.0.0 and indicated the destination subnet/host with ID, then it works fine~
Protect yourself~ http://www.secunia.com MBCS CEH FCNSA
Protect yourself~ http://www.secunia.com MBCS CEH FCNSA
Not applicable

Hey Wc. What I think DDNS does is just notice the IP that the other end has when doing the tunnel negotiation, once generated the DDNS provider has little to do with it until re-negotiated... Probably has more to do with latency and/or link saturation between continents... Try going with aggressive and dialup to do testing using IP' s instead of names.. You' ll probably have the same response as you did with names... Just an idea... hope it gets better! (how about trying 3DES or AES128 for encrypting... they are less complex than AES256, what are you using BTW?)
wcbenyip
New Contributor III

Indeed, the DDNS could not resolve the dynamic IP address... it doesn' t work... so I have to set the IP as " 0.0.0.0" for dialup mode, and then specify the destination ip subnet with Host ID. Thus, the point is: The Forticlient could not resolve the ddns to build up the vpn tunnel. I am already using aggressive mode with only des and md5 as it' s a trial version...
Protect yourself~ http://www.secunia.com MBCS CEH FCNSA
Protect yourself~ http://www.secunia.com MBCS CEH FCNSA
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors