I'm running IPSEC-VPN (AES256/SHA256/DH14) tunnel between a PaloAlto PA-500 and a Fortigate 110C via Internet (10MBit up/down guaranteed both sides - latency between 40 and 50ms).
90% connections are ICA/HDX connections (TCP 1494 and 2598) for XenDesktop connections.
The connection is working not very well. The ICA-sessions are quite stable most of the time but some hangs and freezes from time to time and very low file transfer speeds of physical clients. So I captured data at a tunnel end and saw that I have a huge amount of retransmissions/duplicates ACKs/reassembly errors/...). There are about 15 to 40% of all packets through my tunnel are Dups ands Retrans packets.
Can anybody help me where to start my debugging/solving? I think this are the causes of my problems - right?
Thanks a lot for any help!
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!
The Live Community thanks you for your participation!