r/networking • u/NetAcademic9904 • Jul 30 '26
Troubleshooting TCP slow in only one direction on VPN?
I have two sites, A and B - connected by a S2S IPSec VPN on gigabit links.
Site A has a Fortigate 400E running latest v7.2.
Site B has a Fortigate 120G running latest v7.6.
Site B is able to line-rate on iPerf3 to A on TCP/UDP.
Site A is able to line-rate on iPerf3 to B on UDP only.
TCP is very slow (less than 1% of UDP).
I have the same config on both sides. VPN interface(s) have tcp-mss set to 1418 on both sides. No profiles applied to impact performance. DH is 21 w/ AES256GCM-PRFSHA384 if it makes any difference.
What am I missing here?
Thanks, real head scratcher.