High count of packet retransmissions/Dups over IPSEC/VPN

Reply
Highlighted

High count of packet retransmissions/Dups over IPSEC/VPN

Hi!   

I'm running IPSEC-VPN (AES256/SHA256/DH14) tunnel between a PaloAlto PA-500 and a Fortigate 110C via Internet (10MBit up/down guaranteed both sides - latency between 40 and 50ms).

90% connections are ICA/HDX connections (TCP 1494 and 2598) for XenDesktop connections.

The connection is working not very well. The ICA-sessions are quite stable most of the time but some hangs and freezes from time to time and very low file transfer speeds of physical clients. So I captured data at a tunnel end and saw that I have a huge amount of retransmissions/duplicates ACKs/reassembly errors/...). There are about 15 to 40% of all packets through my tunnel are Dups ands Retrans packets.

Can anybody help me where to start my debugging/solving? I think this are the causes of my problems - right?

e.g. ICA-Traffic

e.g. ICA-Traffic

 

e.g. RDP-Traffic e.g. RDP-Traffic

 

Thanks a lot for any help!

Stony

Highlighted
L0 Member

Hello,

I have the same problme. Have you solve it?

Highlighted
L3 Networker

Hello

 

any solution for that ?

Regards

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!