Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
GG
New Contributor

Same data stream loss on IPSEC VPN between 2 Fortigate FW

Hi,

i have a IPSEC Routed VPN between 2 Fortigate and for one week it happens that same protocols have problem with data stream such as SSH, VNC and RDP if the connection starting from one network, but it's ok from other network.

 

--------A-----------                 |------------------VPN---------------|                   ---------B---------

|  192.168.2.0/24 |-----------FG A ----------| INTERNET |---------FG B-----------|  192.168.0.0/24 |

--------------------                                    --------------                                   --------------------

 This VPN is ok since six years.

 

All connections from B network to A network is ok

Same connections from A network to B network have fails: 1) Ping is ok

2) SSH login is ok, but others commands (like 'ls -lah') fails

3) Same VNC connections is ok (tightVNC), others (Windows CE VNC or Embedded Linux Thin Terminal VNC) dead on data stream

4) SFTP fails ever

5) http and https on B devices (switch, FG B) fails

 

It could be an MTU problem?

any other suggests?

 

 

 

 

 

 

1 REPLY 1
Toshi_Esumi
SuperUser
SuperUser

Sounds like it. Have you tried pinging with a large size packets like 2000 both outside and inside the tunnel? Did the fragmentation work for both cases? Since those are all TCP applications, try like "set tcp-mss 1300" on the interface. I

Labels
Top Kudoed Authors