Hello,
I have a established a VPN between a 300D and a 60D. Users are facing slowness issues.
I have noticed a weird thing! the MTU of the VPN interface is 1446 (enc 3DES) but when I ping remote machines with datasize of 1478 it fails first then it works (ping -f -l 1478 x.x.x.x)
For me, the value shouldn't be bigger than 1418 (as the ping has size of 28 bytes.
I also tried to set MSS on both policies (in/out) on both firewalls to avoid the latency but it didn't help.
Can you help on this topic?
Thanks
Thank you for the reply.
The traffic is correctly offloaded.
I noticed that the MTU is respected if I try to ping the 60D from the 300D but when the users tries to ping -f from a machine behind the 60D to a machine behind the 300D, ping -f -l 1472 works!!!!
it fails the first time then it works.
I even tried to set tcp-mss sender/receiver on both policies of both firewalls BUT it didn't help, ping 1472 still work.
My last failed test was to disable npu offload.
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.