<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Site to site VPN between Azure and VM300 - SQL replication slow in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-vpn-between-azure-and-vm300-sql-replication-slow/m-p/448388#M100811</link>
    <description>&lt;P&gt;Hi, yes I did configure this at security policy.&lt;/P&gt;&lt;P&gt;Unfortunately I can't edit mtu on azure side, cause I'm using azure native virtual gateway.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 18 Nov 2021 12:50:04 GMT</pubDate>
    <dc:creator>infrags</dc:creator>
    <dc:date>2021-11-18T12:50:04Z</dc:date>
    <item>
      <title>Site to site VPN between Azure and VM300 - SQL replication slow</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-vpn-between-azure-and-vm300-sql-replication-slow/m-p/447956#M100764</link>
      <description>&lt;P&gt;Hi folks, I'm facing some throughput issues with a site to site vpn between my onprem site (vm-300) and azure (VpnGw1).&lt;/P&gt;&lt;P&gt;Scenario:&lt;/P&gt;&lt;P&gt;- Windows cluster + SQL Always on Availability Groups (async commit)&lt;/P&gt;&lt;P&gt;- 2 nodes on premises (sql01 and sql02)&lt;/P&gt;&lt;P&gt;- 1 node on azure (sql03).&lt;/P&gt;&lt;P&gt;- Link speed 150Mbps&lt;/P&gt;&lt;P&gt;- Latency between on prem and azure: 15ms&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Ipsec tunnel is working, running some generic tests (iperf and smb copies) the throughput hits:&lt;/P&gt;&lt;P&gt;on-prem to azure: 80Mbps&amp;nbsp;&lt;/P&gt;&lt;P&gt;azure to on-prem: 150Mbps&lt;/P&gt;&lt;P&gt;The issue is when SQL trying to replicate.&lt;/P&gt;&lt;P&gt;The sql01 is my primary, so it is the one who replicate data to secondaries (sql02 and sql03)&lt;/P&gt;&lt;P&gt;Throughput replication from sql01 to sql02 it's around 2.5Mbps (lan connection)&lt;/P&gt;&lt;P&gt;Throughput replication from sql01 to sql03 it's around 1Mbps. (which goes through the vpn).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Selection_112.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/37680i4E95D3FAD48B4581/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Selection_112.png" alt="Selection_112.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Changes made:&lt;/P&gt;&lt;P&gt;- Tunnel MTU to 1400&lt;/P&gt;&lt;P&gt;- Disable Anti replay protect&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I did some captures with packet-capture and I could observe high TCP out-of-order and TCP Previous segment not captured.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope some one could help me.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 16 Nov 2021 20:46:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-vpn-between-azure-and-vm300-sql-replication-slow/m-p/447956#M100764</guid>
      <dc:creator>infrags</dc:creator>
      <dc:date>2021-11-16T20:46:14Z</dc:date>
    </item>
    <item>
      <title>Re: Site to site VPN between Azure and VM300 - SQL replication slow</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-vpn-between-azure-and-vm300-sql-replication-slow/m-p/448090#M100778</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/136419"&gt;@infrags&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;SQL replication kind of hates latency, but inspecting it can also cause serious delays. Do you have a need to inspect the replication traffic? If you do, are you inspecting it on just one or both firewalls?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Nov 2021 01:20:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-vpn-between-azure-and-vm300-sql-replication-slow/m-p/448090#M100778</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2021-11-17T01:20:26Z</dc:date>
    </item>
    <item>
      <title>Re: Site to site VPN between Azure and VM300 - SQL replication slow</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-vpn-between-azure-and-vm300-sql-replication-slow/m-p/448171#M100790</link>
      <description>&lt;P&gt;Yes.&lt;/P&gt;&lt;P&gt;I did on security rule by checking&amp;nbsp;&lt;SPAN&gt;Disable Server Response Inspection, also I have create an application override for mssql server always on port (5022).&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Nov 2021 13:31:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-vpn-between-azure-and-vm300-sql-replication-slow/m-p/448171#M100790</guid>
      <dc:creator>infrags</dc:creator>
      <dc:date>2021-11-17T13:31:12Z</dc:date>
    </item>
    <item>
      <title>Re: Site to site VPN between Azure and VM300 - SQL replication slow</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-vpn-between-azure-and-vm300-sql-replication-slow/m-p/448243#M100795</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;Instead of app overrides, I would just configure a security policy to allow the traffic, source ip/destination ip, with no inspection enabled. This way you get the same results. The other idea I was kicking around was to reduce the MTU on both sides.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Just some thoughts.&lt;/P&gt;</description>
      <pubDate>Wed, 17 Nov 2021 19:28:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-vpn-between-azure-and-vm300-sql-replication-slow/m-p/448243#M100795</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2021-11-17T19:28:54Z</dc:date>
    </item>
    <item>
      <title>Re: Site to site VPN between Azure and VM300 - SQL replication slow</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-vpn-between-azure-and-vm300-sql-replication-slow/m-p/448388#M100811</link>
      <description>&lt;P&gt;Hi, yes I did configure this at security policy.&lt;/P&gt;&lt;P&gt;Unfortunately I can't edit mtu on azure side, cause I'm using azure native virtual gateway.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 18 Nov 2021 12:50:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-vpn-between-azure-and-vm300-sql-replication-slow/m-p/448388#M100811</guid>
      <dc:creator>infrags</dc:creator>
      <dc:date>2021-11-18T12:50:04Z</dc:date>
    </item>
    <item>
      <title>Re: Site to site VPN between Azure and VM300 - SQL replication slow</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-vpn-between-azure-and-vm300-sql-replication-slow/m-p/448459#M100818</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;Then MTU resizing wont help out. I would say set the PAN MTU size on the tunnel to whatever Azure has theirs set to. Sorry I could be much more help.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Thu, 18 Nov 2021 17:12:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-vpn-between-azure-and-vm300-sql-replication-slow/m-p/448459#M100818</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2021-11-18T17:12:24Z</dc:date>
    </item>
    <item>
      <title>Re: Site to site VPN between Azure and VM300 - SQL replication slow</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-vpn-between-azure-and-vm300-sql-replication-slow/m-p/449978#M100995</link>
      <description>&lt;P&gt;Hello everyone, after some weeks of analyzes and debug finally we solved the problem.&lt;BR /&gt;Due different disk sector size on azure VMs, 512 bytes on premises and 4k on azure, we must enable sql trace flag 1800 on on-premises VMs.&lt;BR /&gt;After that the sql replication is working like a charm.&lt;/P&gt;&lt;P&gt;Find below KB about this issue.&lt;BR /&gt;&lt;A href="https://support.microsoft.com/en-us/topic/kb3009974-fix-slow-synchronization-when-disks-have-different-sector-sizes-for-primary-and-secondary-replica-log-files-in-sql-server-ag-and-logshipping-environments-ed181bf3-ce80-b6d0-f268-34135711043c" target="_blank" rel="noopener"&gt;https://support.microsoft.com/en-us/topic/kb3009974-fix-slow-synchronization-when-disks-have-different-sector-sizes-for-primary-and-secondary-replica-log-files-in-sql-server-ag-and-logshipping-environments-ed181bf3-ce80-b6d0-f268-34135711043c&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 29 Nov 2021 13:11:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-vpn-between-azure-and-vm300-sql-replication-slow/m-p/449978#M100995</guid>
      <dc:creator>infrags</dc:creator>
      <dc:date>2021-11-29T13:11:33Z</dc:date>
    </item>
  </channel>
</rss>

