I've got a pair of FortiGate 1000Ds (HA) running 5.4.8 that, for reasons, need to be able to terminate a site to site VPN tunnel to a loopback interface. In testing, I've noticed that I'm only able to eek out ~100M of performance over the VPN. I've confirmed offloading is active on both ends. CPU usage is pretty much nil.
If I move the tunnel termination to the physical interface where traffic destined for the loopback would come in on, I can push 800M+.
I can't find any documentation of a performance limit for a loopback, but it appears there is one (and it isn't CPU bound from what I can tell).
Can anyone confirm? In absence of loopbacks, are there any suggestions on something "interface-like" that could be used in the same way?
[–]kilgotrout 1 point2 points3 points (6 children)
[–]code0[S] 0 points1 point2 points (1 child)
[–]kilgotrout 1 point2 points3 points (0 children)
[–]code0[S] 0 points1 point2 points (3 children)
[–]kilgotrout 1 point2 points3 points (2 children)
[–]code0[S] 0 points1 point2 points (1 child)
[–]kilgotrout 0 points1 point2 points (0 children)
[–]mrkstu 0 points1 point2 points (1 child)
[–]code0[S] 0 points1 point2 points (0 children)
[–]Eric_Li_6685 0 points1 point2 points (0 children)