[SOLVED] RDP over VPN is slow after switch from DPI to SPI

Security Parameter Index SPI, Security Policy Database SPD An SPI is a 32-bit number that is used to uniquely identify a particular SA for any connected device. A Security Association (SA) is an agreement between two devices about how to protect information during communication. It also indicates the parameters, such as keys and algorithms. Traffic Selectors in Route-Based VPNs - TechLibrary SRX Series,vSRX. Understanding Traffic Selectors in Route-Based VPNs, Example: Configuring Traffic Selectors in a Route-Based VPN

When the IPSec peer receives the packet, it looks up the SA in its database by destination address and SPI, and then processes the packet as required. In summary, the SA is a statement of the negotiated security policy between two devices. Figure 1-22 shows an example of differing policies between peers.

The SPI value is inserted in the ESP header of the packet leaving the router. At the other side of the tunnel, the SPI value inserted into the ESP header enables the router to reach parameters and keys that have been dynamically agreed upon during IKE negotiations, or session key refreshment in case of lifetime timeout.

Aug 17, 2017

The actual SPI values for each tunnel are displayed using the diag vpn tun list command on the FortiGate unit. Knowing this, you can enable the sniffer on the external interface, and see if the packets that you are receiving from the remote IPSec client/gateway, do indeed use the correct SPI, or not.