Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
elyes
New Contributor

traffic flow over IPsec very slow

Hello,

I have a established a VPN between a 300D and a 60D. Users are facing slowness issues.

I have noticed a weird thing! the MTU of the VPN interface is 1446 (enc 3DES) but when I ping remote machines with  datasize of 1478 it fails first then it works (ping -f -l 1478  x.x.x.x)

For me, the value shouldn't be bigger than 1418 (as the ping has size of 28 bytes.

I also tried to set MSS on both policies (in/out) on both firewalls to avoid the latency but it didn't help.

 

Can you help on this topic?

Thanks

10 REPLIES 10
elyes
New Contributor

Thank you for the reply.

The traffic is correctly offloaded.

I noticed that the MTU is respected if I try to ping the 60D from the 300D but when the users tries to ping -f from a machine behind the 60D to a machine behind the 300D, ping -f -l 1472 works!!!!

it fails the first time then it works.

 

I even tried to set tcp-mss sender/receiver on both policies of both firewalls BUT it didn't help, ping 1472 still work.

 

My last failed test was to disable npu offload.

Labels
Top Kudoed Authors