Hi,
I have a site to site VPN set up between two fortigates (60e and 500d). I've noticed a latency of 9000ms for TCP connections but 30ish for ICMP - when I complete PCAPs on both tunnel end points I can observe two SYNs (retransmission) entering the tunnel at the 500d side, but only one on the remote end.
Ive confirmed this isnt affecting internet bound traffic, just traffic across the tunnel which is one /24 range.
Ive tried lowering the MSS via policy to 1300 but I see the same results. Ive also brought parity to both ends as in hardcoded one set of proposals and configuring both in interface mode, which they weren't before.
This appears to be repeatable behaviour in which the first SYN is always lost. Any suggestions before I give up on IT and become a baker?