Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
mspada
New Contributor II

VPN IPsec with dh 32

Today I configured a FGT200E with an IPsec VPN with a PFsense. For the first time I used the DH32 (elliptic curve) in phase 1 (AES256, SHA256). no PFS in phase 2. Do you think we have problems with slow communication? If so, which protocols might it affect?

Thank you.

Regards.

Marco Spada

W3 - Italy

Marco Spada
Marco Spada
2 Solutions
ozkanaltas
Contributor III

Hello @mspada ,

 

This unit FG200E, offers 7.2GBit IPSEC VPN throughput with Aes256, Sha256 algrotihm. 

 

If you don't have much more ipsec traffic for example more than 5Gbit. I think you will not see latency problems on your ipsec traffic outside of normal ipsec latency. 

 

https://www.fortinet.com/content/dam/fortinet/assets/data-sheets/FortiGate_200E_Series.pdf

 

If you have found a solution, please like and accept it to make it easily accessible to others.
NSE 4-5-6-7 OT Sec - ENT FW

View solution in original post

If you have found a solution, please like and accept it to make it easily accessible to others.NSE 4-5-6-7 OT Sec - ENT FW
smaruvala
Staff
Staff

Hi,

 

Ideally it should not have an impact as it is used for key exchange purposes only. 

 

Regards,

Shiva

View solution in original post

2 REPLIES 2
ozkanaltas
Contributor III

Hello @mspada ,

 

This unit FG200E, offers 7.2GBit IPSEC VPN throughput with Aes256, Sha256 algrotihm. 

 

If you don't have much more ipsec traffic for example more than 5Gbit. I think you will not see latency problems on your ipsec traffic outside of normal ipsec latency. 

 

https://www.fortinet.com/content/dam/fortinet/assets/data-sheets/FortiGate_200E_Series.pdf

 

If you have found a solution, please like and accept it to make it easily accessible to others.
NSE 4-5-6-7 OT Sec - ENT FW
If you have found a solution, please like and accept it to make it easily accessible to others.NSE 4-5-6-7 OT Sec - ENT FW
smaruvala
Staff
Staff

Hi,

 

Ideally it should not have an impact as it is used for key exchange purposes only. 

 

Regards,

Shiva

Labels
Top Kudoed Authors