Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
AdamC
New Contributor

Authentication delay between two sites with IPSec VPN

We have two sites; each has an Active Directory domain; the domains are in two-way trust.  The users at the remote site connect, through an IPSec VPN connection (originally between Cisco devices then Sonicwall now Fortinet) via RDP, to an application server at the local site.  We installed a Fortigate 400 at the local site; no one at the remote site complained of bad performance.  Later we installed a Fortigate 80 at the remote site; immediately the users at the remote site began to complain of slow logon to the application server.

 

Any RDP connection to the application server at the local site as a user at the remote site, regardless of location of client computer, sees a very slow negotiation of RDP then very slow Windows logon - 30+ seconds for each step. We have only IPv4 traffic over the VPN tunnell and policies for the VPN tunnel wide-open (all services and specific subnets), inbound and outbound, on both Fortigate units.  The best clue is an event log on the application server, mentioning delays in applying group policies from the remote user's domain.

 

I have attempted a packet sniff on both units, but I see the delays but nothing odd.  What else should I try?

0 REPLIES 0
Labels
Top Kudoed Authors