Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
mimetist
New Contributor

VDOM performance impact

Hi,

 

I am trying to understand what will the performance impact of adding a new VDOM that will be used as site-to-site VPN concentrator. Total number of IPSec VPN tunnels will be about 100 with summary throughput up to 2Gbps. Quite possible the number of IPSec tunnels will grow in the future. Does Fortinet have any best practices for this kind of scenario? 

3 REPLIES 3
Toshi_Esumi
SuperUser
SuperUser

Although I don't know if such documentation is available, I wouldn't expect much difference. But if NP6 supported model, make sure to follow the doc below so use the same NPU from ingress to egress of VPN traffic. That definitely affects to VPN performance.

https://fortinetweb.s3.amazonaws.com/docs.fortinet.com/v2/attachments/e564ec10-1a20-11e9-9685-f8bc12...

 

hklb

toshiesumi wrote:

Although I don't know if such documentation is available, I wouldn't expect much difference. But if NP6 supported model, make sure to follow the doc below so use the same NPU from ingress to egress of VPN traffic. That definitely affects to VPN performance.

https://fortinetweb.s3.amazonaws.com/docs.fortinet.com/v2/attachments/e564ec10-1a20-11e9-9685-f8bc12...

 

Hi,

 

Do you have an explaination ? I don't understand why it would cause an impact (most of FGT has an ISF)

 

Lucas

Toshi_Esumi

I don't know if NPU offloading can actually happen when the ingress belongs to npu0 and the vdom-link to hand out belongs to npu1 (maybe described at somewhere in the doc). But easily understand it needed to be pulled out from the NPU back to the CPU to put back in another NPU. Then same thing needs to happen on the egress vdom if npu mismatches there as well.

Labels
Top Kudoed Authors