<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: GlobalProtect SSL vs IPSec in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-ssl-vs-ipsec/m-p/383119#M858</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/118537"&gt;@Scott.Ainslie&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Here is main reason for slowness over SSL&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;GlobalProtect is slower on SSL VPN because SSL requires more overhead than IPSec. Also, Transmission Control Protocol (TCP) is more prone to latency than User Datagram Protocol (UDP), which is used in IPsec GlobalProtect.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Hope this helps.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Regards&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Sun, 31 Jan 2021 04:56:28 GMT</pubDate>
    <dc:creator>MP18</dc:creator>
    <dc:date>2021-01-31T04:56:28Z</dc:date>
    <item>
      <title>GlobalProtect SSL vs IPSec</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-ssl-vs-ipsec/m-p/382997#M857</link>
      <description>&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;Help me come to grips with this. I recently enabled IPSec on our PAN for end user VPN's. I did it primarily to hopefully get improved VoIP performance, less jitter, and perhaps a marginal speed improvement. What I have found is an almost across the board doubling of download speeds.&lt;/P&gt;&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;If you consider that most of my users are on regular consumer Xfinity cable links when using SSL their speed test would average around 15 - 20Mbps. Switching to IPSec changes that to 30 - 50Mbps pretty reliably. Happy, but not what I was expecting and I am trying to understand where the bottleneck is in SSL?&lt;/P&gt;&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;Both data and management CPU's are running mostly below the 20's and haven't noticeably changed after moving to IPSec. I know that IPSec has lower overhead, quicker connection establishment and doesn't suffer from the TCP inside TCP that SSL (TLS) has but I wasn't expecting this big of a difference. I am left thinking the bottleneck is in the encryption methods either on the firewall or in the GlobalProtect client.&lt;/P&gt;&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;PanOS 9.1.4, GlobalProtect 5.2.3&lt;/P&gt;&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;Thoughts?&lt;/P&gt;</description>
      <pubDate>Fri, 29 Jan 2021 22:11:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-ssl-vs-ipsec/m-p/382997#M857</guid>
      <dc:creator>Scott.Ainslie</dc:creator>
      <dc:date>2021-01-29T22:11:06Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect SSL vs IPSec</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-ssl-vs-ipsec/m-p/383119#M858</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/118537"&gt;@Scott.Ainslie&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Here is main reason for slowness over SSL&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;GlobalProtect is slower on SSL VPN because SSL requires more overhead than IPSec. Also, Transmission Control Protocol (TCP) is more prone to latency than User Datagram Protocol (UDP), which is used in IPsec GlobalProtect.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Hope this helps.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Regards&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 31 Jan 2021 04:56:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-ssl-vs-ipsec/m-p/383119#M858</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2021-01-31T04:56:28Z</dc:date>
    </item>
  </channel>
</rss>

