Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Bgoines
New Contributor

VPN High Latency

I have a FG 110C at my main location with a 50/50 mbs fiber connection as my isp. I have a fortigate 60c at my remote locations. At 2 of the locations in question, I have 5mb/5mb pipes. These two locations have higher latency (60ms) to my main location that my other two locations with 3mb pipes (15ms). Could there be a problem with my ipsec vpn tunnels? The two locations in question have very low latency to locations such as Google or yahoo or any other website. The only time that there is high latency is from site to site.
5 REPLIES 5
ede_pfau
SuperUser
SuperUser

The only thing that crossed my mind is " what if IPsec traffic is not accelerated on the remote FGTs?" . You can check that easily from the CLI.
Ede Kernel panic: Aiee, killing interrupt handler!
Ede Kernel panic: Aiee, killing interrupt handler!
Bgoines

What is the command for this?
emnoc
Esteemed Contributor III

Yes the following cmd show soft vrs hardware process FG100C3G08338342 # get vpn ipsec stats crypto IPsec crypto devices in use: CP6 (encrypted/decrypted): null: 0 0 des: 0 0 3des: 11095399 5680328 aes: 2190 2190 CP6 (generated/validated): null: 0 0 md5: 0 0 sha1: 11097589 5682518 sha256: 0 0 4: 0 0 5: 0 0 SOFTWARE (encrypted/decrypted): null: 0 0 des: 0 0 3des: 0 0 aes: 0 0 SOFTWARE (generated/validated): null: 0 0 md5: 0 0 sha1: 0 0 sha256: 0 0 4: 0 0 5: 0 0 Unless you disable it from the vpn config, the FGT110 should process these via the CP6 ASIC. btw this is 4.3p17 on a FGT110C with approx 7 active tunnels or more get vpn ipsec stats tunnel tunnels total: 8 static/ddns: 8 dynamic: 0 manual: 0 errors: 1 selectors total: 12 up: 7

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
Bgoines
New Contributor

These are my results... MROUTER # get vpn ipsec stats crypto IPsec crypto devices in use: CP6 (encrypted/decrypted): null: 0 0 des: 0 0 3des: 1128807026 969056953 aes: 0 0 CP6 (generated/validated): null: 0 0 md5: 0 0 sha1: 1128807026 969056953 sha256: 0 0 4: 0 0 5: 0 0 SOFTWARE (encrypted/decrypted): null: 0 0 des: 0 0 3des: 0 0 aes: 0 0 SOFTWARE (generated/validated): null: 0 0 md5: 0 0 sha1: 0 0 sha256: 0 0 4: 0 0 5: 0 0
emnoc
Esteemed Contributor III

Okay nothing is kicked up to the CP6 and my bad the NPU offloading is not available in a FGT110C. So you can rule out any thing handle within software per-se.

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors