High count of packet retransmissions/Dups over IPSEC/VPN

Showing results for 
Show  only  | Search instead for 
Did you mean: 

High count of packet retransmissions/Dups over IPSEC/VPN


I'm running IPSEC-VPN (AES256/SHA256/DH14) tunnel between a PaloAlto PA-500 and a Fortigate 110C via Internet (10MBit up/down guaranteed both sides - latency between 40 and 50ms).

90% connections are ICA/HDX connections (TCP 1494 and 2598) for XenDesktop connections.

The connection is working not very well. The ICA-sessions are quite stable most of the time but some hangs and freezes from time to time and very low file transfer speeds of physical clients. So I captured data at a tunnel end and saw that I have a huge amount of retransmissions/duplicates ACKs/reassembly errors/...). There are about 15 to 40% of all packets through my tunnel are Dups ands Retrans packets.

Can anybody help me where to start my debugging/solving? I think this are the causes of my problems - right?

e.g. ICA-Traffic

e.g. ICA-Traffic


e.g. RDP-Traffic e.g. RDP-Traffic


Thanks a lot for any help!



L0 Member


I have the same problme. Have you solve it?



any solution for that ?


  • 2 replies
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!