- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
ipsec VPN issue
Could you advise if there are any methods to diagnose the quality of an IPsec VPN? I've noticed that the speed between my two site-to-site IPsec connections is quite slow. However, when I switch to OpenVPN, the speed returns to normal Could there be any settings that might be affecting this? Thanks.
- Labels:
-
FortiGate
-
FortiGate-VM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi 52000cc,
You can check for NPU offloading settings: Check if NPU offloading is enabled or disabled.
- Drops on NPU chips: Look for any drops on the NPU chips.
- CPU/Memory utilization: Monitor the FortiGate's CPU and memory utilization for any anomalies.
Please refer to the below document on how to troubleshoot speed issue through IPsec tunnel using iperf tool:
I hope it helps!
Regards,
Aman
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Could you please let me know where to find the NPU offloading settings? Also, which command should be used to enable it? I am using the VM version, which does not have an NPU chip.Thanks
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Below are the results of my iperf3 test. The reverse direction speed appears abnormal. Could you please advise if there is any misconfiguration causing this issue?
ipesec iperf3 test speed:
[ ID] Interval Transfer Bitrate
[ 5] 0.00-10.01 sec 218 MBytes 182 Mbits/sec sender
[ 5] 0.00-10.09 sec 217 MBytes 181 Mbits/sec receiver
ipesec iperf3 -R test speed:
[ ID] Interval Transfer Bitrate
[ 5] 0.00-10.01 sec 21.1 MBytes 17.7 Mbits/sec sender
[ 5] 0.00-10.01 sec 20.9 MBytes 17.5 Mbits/sec receiver
openvpn iperf3 test speed:
[ ID] Interval Transfer Bitrate
[ 5] 0.00-10.02 sec 161 MBytes 135 Mbits/sec sender
[ 5] 0.00-10.03 sec 161 MBytes 135 Mbits/sec receiver
openvpn iperf3 -R test speed:
[ ID] Interval Transfer Bitrate
[ 5] 0.00-10.02 sec 204 MBytes 171 Mbits/sec sender
[ 5] 0.00-10.02 sec 203 MBytes 170 Mbits/sec receiver
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello @52000cc ,
You can try disabling NPU offload:
https://community.fortinet.com/t5/FortiGate/Technical-Tip-Ensuring-IPSec-traffic-is-offloaded-for-im...
Also check these articles:
https://community.fortinet.com/t5/FortiGate/Technical-Tip-Setting-TCP-MSS-value/ta-p/194518
https://community.fortinet.com/t5/Support-Forum/IPSEC-VPN-Very-SLOW/td-p/245271
Regards,
Varun
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Can virtual machines support NPU? The command output shows npu_flag=00. Should I enable it, or is it not applicable?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello @52000cc ,
The VM-based FortiGates do not have NPUs and rely on CPU processing for IPsec encryption and decryption.
Regards
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Okay, so I don't need to adjust any NPU-related settings, right? Then what could be causing the issue, and which settings should I adjust?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi @52000cc
The NPU offloading does not happen in VM fortigate.
Usually the issue is the speed between the two WAN links being slower than expected.
You can test for this by doing Iperf test between WAN links of the two sides:
Regards,
Varun
