Lowering MTU on FortiClient IPsec VPN due to drops
We recently migrated to FortiClient (Managed by FortiClient EMS) with IPSec VPN, overall it's been successful for 90% of our users. However, we have a few users where either the VPN will drop completely or it will stay connected, but traffic will stop flowing so office apps for example stop working.
We are on 7.4.7 for Forticlient as the Fortigate is on 7.4.11, which sits behind another Fortigate that's on 7.4.8, we just port forward the required ports for the VPN to work. I know we could've done local in to due security policies and not need two set's of Fortigates, but we have a requirement for the remote access VPN to not reside on the primary firewall.
Anyways, I've made a new policy in FortiClient EMS that drops the MTU from 1280(default) to 1250 and that has fixed the VPN drops for a few users. I was just curious if anyone else has had similar issues on the IPSec VPN.