<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: GlobalProtect Slowness in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-slowness/m-p/480431#M2671</link>
    <description>&lt;P&gt;Just a follow up on my post.&amp;nbsp; &lt;STRONG&gt;We enabled IPSEC on GlobalProtect and all our slowness issues were resolved (we get nearly full bandwidth).&lt;/STRONG&gt;&amp;nbsp; &amp;nbsp;I still find it hard to believe that SSL VPN performance is so terrible and that Palo Alto is happy with it, but we've moved on to just requiring IPSEC.&lt;/P&gt;</description>
    <pubDate>Thu, 14 Apr 2022 18:34:34 GMT</pubDate>
    <dc:creator>svintinner</dc:creator>
    <dc:date>2022-04-14T18:34:34Z</dc:date>
    <item>
      <title>GlobalProtect Slowness</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-slowness/m-p/391893#M1029</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I recently started a new job and have been thrown right into the fire.&amp;nbsp; Users are complaining about very slow connections from globalprotect.&amp;nbsp; They get speed tests between 3mbps - 20mbps.&amp;nbsp; Internet speed from ISP is 500Mbps.&amp;nbsp; When I attempt from a speed test site, I get a little over 100Mbps off the network but around 20Mbps when I'm on GlobalProtect.&amp;nbsp; This is not split tunnel.&amp;nbsp; Globalprotect connections are IPSec VPN&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I don't want to jump to conclusions but I believe the issue is inadequate hardware.&amp;nbsp; Firewall is a PA-3050.&amp;nbsp; When I check the specs, I see max IPsec throughput is 500Mbps.&amp;nbsp; There are over 100 users connecting to globalprotect during peak times.&amp;nbsp; Assuming my understanding is correct, those 100 users are going to be sharing the 500 Mbps throughput?&amp;nbsp; Plus the profiles attached to the security policy rules (av, threat, url, decryption) add some overhead, I'm not entirely sure how much that would impact though.&amp;nbsp; &amp;nbsp;The firewall also has some site-to-site VPNs too.&amp;nbsp; Would Globalprotect share the 500Mbps throughput with those Site-to-Site VPNs too, or is that 500Mbps per tunnel interface?&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've also heard similar complaints from other Palo customers who blame the issue on globalprotect, but I'm not sure if there is truth to that, so I don't want to assume&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any advice would be helpful&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 18 Mar 2021 01:53:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-slowness/m-p/391893#M1029</guid>
      <dc:creator>ce1028</dc:creator>
      <dc:date>2021-03-18T01:53:49Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect Slowness</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-slowness/m-p/392199#M1030</link>
      <description>&lt;P&gt;When trying to troubleshoot slowness, a lot of things can affect the speed.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Max Throughput .. not sure if "per tunnel" or total for machine..&amp;nbsp; hard to say.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The Policies can affect things, but also the versions can have a huge effect on everything.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What versions are we dealing with here? PAN-OS and GP version?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also, just incase anyone needs it, this is a great document to help troubleshoot GlobalProtect..&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClkBCAS" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClkBCAS&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 18 Mar 2021 19:39:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-slowness/m-p/392199#M1030</guid>
      <dc:creator>jdelio</dc:creator>
      <dc:date>2021-03-18T19:39:33Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect Slowness</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-slowness/m-p/392290#M1031</link>
      <description>&lt;P&gt;Thanks for reply.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In this case, version does not appear to be relevant. Before I joined the previous engineer upgraded firewall and gp version to 9.0.11 and 5.1.7.&amp;nbsp; Apparently, issue has been going on since 8.1 days from what I gather&lt;/P&gt;</description>
      <pubDate>Fri, 19 Mar 2021 14:14:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-slowness/m-p/392290#M1031</guid>
      <dc:creator>ce1028</dc:creator>
      <dc:date>2021-03-19T14:14:15Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect Slowness</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-slowness/m-p/392421#M1032</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/71649"&gt;@ce1028&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;One thing first I will recommend to upgrade OS on firewall to 9.1.7 and GP to version 5.1.8.&lt;/P&gt;
&lt;P&gt;Are you doing any ssl decryption on the firewall?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Check the firewall interface for any errors or speed duplex mismatch?&lt;/P&gt;
&lt;P&gt;Does firewall has direct connection to the internet?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Sat, 20 Mar 2021 03:16:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-slowness/m-p/392421#M1032</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2021-03-20T03:16:37Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect Slowness</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-slowness/m-p/392741#M1038</link>
      <description>&lt;P&gt;&lt;STRONG&gt;For the guys that have replied, I'm curious what kind of performance you see on your GlobalProtect sessions?&amp;nbsp; &lt;/STRONG&gt;I think it might be helpful to set a baseline when talking about GlobalProtect performance.&amp;nbsp; I've read tons of these posts on the forums, but rarely see anyone discuss what we should expect.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In my testing I can never average more than 50-70 mbps GlobalProtect SSL VPN connection (dedicated 3020 firewall with just me,&amp;nbsp; dedicated 1 Gbps internet link on both sides for just me, 30ms latency, no inspection or app-id, no QoS, iperf3).&amp;nbsp; I can open a second SSL VPN connection from a different computer and simultaneously get another 50-70 mbps without impacting the first session.&amp;nbsp; I don't see a significant CPU load on the firewall at either point.&amp;nbsp; I can do testing outside GlobalProtect (static NAT) and pretty consistently get 940 mbps.&amp;nbsp; My assumption is that this is some internal tuning limitations that we can't see.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;On my production system, I will have stretches where I can get 50-70 mbps, but this will frequently drop down to the 2-10 mbps range (for minutes at a time).&amp;nbsp; Like the OP, the overall bandwidth usage doesn't explain all of the issues). &amp;nbsp; Certainly, I can see slowness when there are peaks in bandwidth usage, but I also see slowness that doesn't correspond to any bandwidth usage.&amp;nbsp; My assumption is that it is due to firewall load (although the firewall doesn't show 100% CPU, I assume the GP process is somehow throttled and that the performance slowness is due to other stream processing inspections and app-id that is happening).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I can run a simultaneous test (iperf3) where I test using a static NAT (non-GP) at 200 mbps, along side 2 GP connections.&amp;nbsp; The static NAT connection will remain consistent, while the two GP connections will suffer performance hits around the same time.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I should note that I've read the usual comments about SSL VPN and performance (due to a TCP session encapsulated in another TCP session).&amp;nbsp;&amp;nbsp; I can see this demonstrated when I do testing at my DR site and I run into (what I assume) are throttling issues when the interior and exterior TCP sessions have conflicting sliding windows.&amp;nbsp; For example, the session will be cooking along at 70mbps for 30 seconds, then drop to zero and then ramp back up to 70 mbps.&amp;nbsp;&amp;nbsp; I'm planning to do some testing on my test site with GlobalProtect in IPSEC mode to see if this goes away or if my overall bandwidth is improved.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Anyway here are some things I've noticed (recognizing this is the blind leading the blind), in case any of it give you some things to check on your system:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;As mentioned above, no matter what your bandwidth, Globalprotect seems to have other limitations, so setting expectations with users is critical.&amp;nbsp; (i.e. a Speedtest is never going to show the full bandwidth).&lt;/LI&gt;&lt;LI&gt;Regular SMB performance is just awful on SSL VPN.&amp;nbsp; It works better if you use SMBv3, so ensure that your clients and file servers are upgraded.&lt;/LI&gt;&lt;LI&gt;In my testing just enabling QoS on an interface caused significant performance hit on GlobalProtect.&lt;/LI&gt;&lt;LI&gt;Security policies (inspections) can impact performance.&amp;nbsp; Try tuning them or turning them off (while testing).&lt;/LI&gt;&lt;LI&gt;Verify you aren't having &lt;A href="https://live.paloaltonetworks.com/t5/globalprotect-articles/troubleshooting-globalprotect-mtu-issues/ta-p/384894" target="_self"&gt;fragmentation issues&lt;/A&gt;.&amp;nbsp; GP 5.2.5 &lt;A href="https://docs.paloaltonetworks.com/globalprotect/5-2/globalprotect-app-new-features/new-features-released-in-gp-app/configurable-maximum-transmission-unit-for-globalprotect-connections.html" target="_self"&gt;supports&lt;/A&gt; changing the MTU size.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If anyone has any better information, especially about the internal workings or scheduling of GP traffic inside the firewall, I'd love to hear it.&lt;/P&gt;</description>
      <pubDate>Mon, 22 Mar 2021 16:31:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-slowness/m-p/392741#M1038</guid>
      <dc:creator>svintinner</dc:creator>
      <dc:date>2021-03-22T16:31:22Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect Slowness</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-slowness/m-p/394187#M1070</link>
      <description>&lt;P&gt;We had lots of speed issues which boiled down to :&lt;/P&gt;&lt;P&gt;- use IPSEC instead of SSL&lt;/P&gt;&lt;P&gt;- check your MTU/fragmented packets (Azure drops out of order packets, limits MTU to 1400 and our local WIFI L3 roaming feature took some MTU size extra away).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 26 Mar 2021 08:46:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-slowness/m-p/394187#M1070</guid>
      <dc:creator>sebastianvd</dc:creator>
      <dc:date>2021-03-26T08:46:56Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect Slowness</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-slowness/m-p/480431#M2671</link>
      <description>&lt;P&gt;Just a follow up on my post.&amp;nbsp; &lt;STRONG&gt;We enabled IPSEC on GlobalProtect and all our slowness issues were resolved (we get nearly full bandwidth).&lt;/STRONG&gt;&amp;nbsp; &amp;nbsp;I still find it hard to believe that SSL VPN performance is so terrible and that Palo Alto is happy with it, but we've moved on to just requiring IPSEC.&lt;/P&gt;</description>
      <pubDate>Thu, 14 Apr 2022 18:34:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-slowness/m-p/480431#M2671</guid>
      <dc:creator>svintinner</dc:creator>
      <dc:date>2022-04-14T18:34:34Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect Slowness</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-slowness/m-p/496853#M2829</link>
      <description>&lt;P&gt;I believe Palo Alto is happier with IPsec, indeed it's the dafault transport method that GP tries when connecting to the gateway.&lt;/P&gt;</description>
      <pubDate>Wed, 01 Jun 2022 09:40:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-slowness/m-p/496853#M2829</guid>
      <dc:creator>m.fusoni</dc:creator>
      <dc:date>2022-06-01T09:40:35Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect Slowness</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-slowness/m-p/497501#M2833</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/23391"&gt;@svintinner&lt;/a&gt;&amp;nbsp; Also IPSEC is UDP it has less overhead as compare to SSL.&lt;/P&gt;
&lt;P&gt;Thanks for updating the Community&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Wed, 01 Jun 2022 20:07:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-slowness/m-p/497501#M2833</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2022-06-01T20:07:31Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect Slowness</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-slowness/m-p/540220#M3977</link>
      <description>&lt;P&gt;I recently found about 30 of my 4,000+ users have crawling speeds (2Mbps) over Global Protect using IPsec when compared to AnyConnect over SSL (30Mbps). During troubleshooting we are certain their ISP is throttling or applying DPI to their IPsec tunnel. To work around their ISP issue, we added the ability for them to connect to Global Protect over SSL (a checkbox in the client settings). Now they are seeing the same speeds as AnyConnect. This may or may not be related to your problem, but something to try in case SSL works faster for them compared to IPsec.&lt;/P&gt;</description>
      <pubDate>Wed, 26 Apr 2023 16:56:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-slowness/m-p/540220#M3977</guid>
      <dc:creator>FBMTRAV</dc:creator>
      <dc:date>2023-04-26T16:56:02Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect Slowness</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-slowness/m-p/1086878#M6368</link>
      <description>&lt;P&gt;i am having a client having the same issue, 10% of the users are facing slowness while 90% are not facing it using IPSec tunnel, while disabling the IPSec and using only SSL it is working fine.&lt;/P&gt;</description>
      <pubDate>Fri, 17 Jan 2025 14:00:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-slowness/m-p/1086878#M6368</guid>
      <dc:creator>Waly</dc:creator>
      <dc:date>2025-01-17T14:00:36Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect Slowness</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-slowness/m-p/1204732#M6379</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/310694"&gt;@Waly&lt;/a&gt;&amp;nbsp;Normally SSL works slower as it is TCP.IPSEC gives faster speed.&lt;/P&gt;
&lt;P&gt;We have both enabled and see connection is slower when using SSL and this is expected behavior.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Jan 2025 17:53:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-slowness/m-p/1204732#M6379</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2025-01-21T17:53:02Z</dc:date>
    </item>
  </channel>
</rss>

