Hello, In case you are using PPP interface, do a packet capture and see
if the TSL server hello leng is bigger than the fortigate MTU. I had a
case where the server was sending the server helo with 1506 length. and
the fortigate had only 1500 MTU. So...
Ok, I'm starting to understand the situation. So you have the Per-IP
traffic shaping applied on the F60E that splits your internet access ?
and is there just 1 user that is able to by pass the shaping policy ?
Have you tried to use some of the debug ...