Fortigate on FIrmware 7.2.3
I have a mikrotik router connecting to a Fortigate 200HA-Cluster via IPSEC.
The externalSite has multiple Subnets, so a GRE Tunnel (over the IPSEC) connects from the Mikrotikrouter to handle the routingrules on the mikrotikside.
I have firewallrules, allowing access to different subnet on the externalSite.
One Subnet on the external side should now use the WAN from the mainsite.
I am routing the 0.0.0.0 via the GREoverIPSEC-Tunnel to the Forti and then make a NAT.
This works fine MOSTLY. Latency, performance, etc. everything is fine.
Youtube.com (and nearly every other website i tested) works fine.
BUT: a group of specific websites doesnt open at all, i get a timeout.
So opening up eg speedtest.net, www.telekom.de oder www.a1.net is not possible.
Maybe its a conincidence, but alle these sites are either speedtestproviders or ISPs
Any idea how I can debug this?
I already thought its an MTU issue and adjusted the MTU on the external site to the MTU of the Fortigate.
If I call an external MTU check (LetMeCheck.it) i get a MTU of 1500 as a result.
The Fortigate tells me the MTU of the GRE Tunnel ist 1396.
Could this be a pointer or is it a red hering?