<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IPSec tunnel slowness issue in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-slowness-issue/m-p/512649#M106517</link>
    <description>&lt;P&gt;Hi Folks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We are having only two ISP each with 100 Mbps bandwidth each. We are using only one ISP interface as primary. Upon checking the below command we had identified the throughput is measuring upto 130-150 Mbps.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN class=""&gt;&amp;gt; show system statistics session&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;After load-balancing the traffic between two ISP's the upload/download speed via the tunnel interface had increased.&lt;/P&gt;</description>
    <pubDate>Tue, 23 Aug 2022 09:07:38 GMT</pubDate>
    <dc:creator>tamilvanan</dc:creator>
    <dc:date>2022-08-23T09:07:38Z</dc:date>
    <item>
      <title>IPSec tunnel slowness issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-slowness-issue/m-p/509395#M106048</link>
      <description>&lt;P&gt;Hi Folks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We had recently configured an IPSec tunnel between the PA and the Cisco Meraki firewall.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The PA firewall is located in India and the Cisco firewall is located in USA.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We are trying to upload an file from an Linux host located behind the PA firewall to an server located behind the Cisco firewall using wget http option from linux machine.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;While uploading we are getting an speed of only 200 kbps. Our ISP bandwidth is 200 Mbps.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Upon taking global counter we could see that the firewall is dropping the packet with the below counter&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN&gt; tcp_drop_packet 2 0 warn tcp pktproc packets dropped because of failure in tcp reassembly&lt;BR /&gt;tcp_exceed_flow_seg_limit 2 0 warn tcp resource packets dropped due to the limitation on tcp out-of-order queue size&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We had changed the MTU on the tunnel interface but no luck. After allowing the out-of-order TCP packets using the below command the speed had increased an bit.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&amp;gt; config&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;# set deviceconfig setting tcp bypass-exceed-oo-queue &amp;lt;yes|no&amp;gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;# commit&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/kcSArticleDetail?id=kA10g000000ClWK" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/kcSArticleDetail?id=kA10g000000ClWK&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Is this an issue with the firewall or issue with the host.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thanks in advance.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 20 Jul 2022 15:35:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-slowness-issue/m-p/509395#M106048</guid>
      <dc:creator>tamilvanan</dc:creator>
      <dc:date>2022-07-20T15:35:23Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec tunnel slowness issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-slowness-issue/m-p/509411#M106051</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;Was the MTU changed on both sides of the tunnel?&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Wed, 20 Jul 2022 18:07:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-slowness-issue/m-p/509411#M106051</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2022-07-20T18:07:23Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec tunnel slowness issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-slowness-issue/m-p/509455#M106059</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/27580"&gt;@OtakarKlier&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Yes we had tried to ping the server on the peer end with the do-not fragment bit enabled and configured the supported MTU value on both side of the tunnel interfaces.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 21 Jul 2022 05:54:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-slowness-issue/m-p/509455#M106059</guid>
      <dc:creator>tamilvanan</dc:creator>
      <dc:date>2022-07-21T05:54:04Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec tunnel slowness issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-slowness-issue/m-p/509549#M106076</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/165087"&gt;@tamilvanan&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;How stable of a connection do you have between sites outside of the tunnel? If your getting so many out of order packets that it's causing issues and the MTU is correct, are you experiencing a larger amount of packet loss between the two nodes themselves?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 21 Jul 2022 22:23:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-slowness-issue/m-p/509549#M106076</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2022-07-21T22:23:40Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec tunnel slowness issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-slowness-issue/m-p/512649#M106517</link>
      <description>&lt;P&gt;Hi Folks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We are having only two ISP each with 100 Mbps bandwidth each. We are using only one ISP interface as primary. Upon checking the below command we had identified the throughput is measuring upto 130-150 Mbps.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN class=""&gt;&amp;gt; show system statistics session&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;After load-balancing the traffic between two ISP's the upload/download speed via the tunnel interface had increased.&lt;/P&gt;</description>
      <pubDate>Tue, 23 Aug 2022 09:07:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-tunnel-slowness-issue/m-p/512649#M106517</guid>
      <dc:creator>tamilvanan</dc:creator>
      <dc:date>2022-08-23T09:07:38Z</dc:date>
    </item>
  </channel>
</rss>

