<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PA-220 Slow Response time connecting over ipsec tunnel to AWS. in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/pa-220-slow-response-time-connecting-over-ipsec-tunnel-to-aws/m-p/537694#M110415</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/254587"&gt;@FMA-Admin&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;That is one of the places you can set MTU and MSS values. If you are looking to adjust the values for your tunnels, you will have to click on the tunnel interface itself.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Network -&amp;gt; Interfaces -&amp;gt; Tunnel -&amp;gt; Select the tunnel used for each VPN -&amp;gt; Advanced Tab&lt;/P&gt;</description>
    <pubDate>Wed, 05 Apr 2023 03:57:31 GMT</pubDate>
    <dc:creator>JayGolf</dc:creator>
    <dc:date>2023-04-05T03:57:31Z</dc:date>
    <item>
      <title>PA-220 Slow Response time connecting over ipsec tunnel to AWS.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-220-slow-response-time-connecting-over-ipsec-tunnel-to-aws/m-p/536856#M110266</link>
      <description>&lt;P&gt;I've read on here multiple posts, older and newer but I think part of my issue is that I'm new to this environment and I'm hoping for a bit of guidance. I took over 4 sites with PA-220 firewalls which were way out of date, I've just got them to 10.0.11 and yes I know I still have a few more to go.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;All 4 sites have a ipsec tunnel to AWS, one of those sites is heavy with accessing network shares stored on AWS. I went through and read the document on&amp;nbsp;When To Use Adjust MSS. Very helpful but here is my question that I'm hoping for a bit of guidance.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000PN0gCAG" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000PN0gCAG&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;After walking through the document I now want to go in and set the MTU to 1360 and MSS to 140 bytes, I feel a good start after the results with the ping, If I'm understanding what I did and the results. I would like to know if the following is the correct spot in the interface to make these changes before I just go in and do it.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Network &amp;gt; Interfaces &amp;gt; Ethernet &amp;gt; ethernet 1/2 Layer 3 &amp;gt; Advanced&lt;/P&gt;
&lt;P&gt;Management Profile MTU - 1360&lt;/P&gt;
&lt;P&gt;Adjust TCP MSS Both ipv4 &amp;amp; 6 set to 140&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="InterfaceMTU.png" style="width: 586px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/49079i8E355EA365B105F4/image-dimensions/586x262/is-moderation-mode/true?v=v2" width="586" height="262" role="button" title="InterfaceMTU.png" alt="InterfaceMTU.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="InterfaceMTUSetting.png" style="width: 591px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/49080i4B834ADBC4058839/image-dimensions/591x422/is-moderation-mode/true?v=v2" width="591" height="422" role="button" title="InterfaceMTUSetting.png" alt="InterfaceMTUSetting.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 29 Mar 2023 03:27:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-220-slow-response-time-connecting-over-ipsec-tunnel-to-aws/m-p/536856#M110266</guid>
      <dc:creator>FMA-Admin</dc:creator>
      <dc:date>2023-03-29T03:27:10Z</dc:date>
    </item>
    <item>
      <title>Re: PA-220 Slow Response time connecting over ipsec tunnel to AWS.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-220-slow-response-time-connecting-over-ipsec-tunnel-to-aws/m-p/537694#M110415</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/254587"&gt;@FMA-Admin&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;That is one of the places you can set MTU and MSS values. If you are looking to adjust the values for your tunnels, you will have to click on the tunnel interface itself.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Network -&amp;gt; Interfaces -&amp;gt; Tunnel -&amp;gt; Select the tunnel used for each VPN -&amp;gt; Advanced Tab&lt;/P&gt;</description>
      <pubDate>Wed, 05 Apr 2023 03:57:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-220-slow-response-time-connecting-over-ipsec-tunnel-to-aws/m-p/537694#M110415</guid>
      <dc:creator>JayGolf</dc:creator>
      <dc:date>2023-04-05T03:57:31Z</dc:date>
    </item>
    <item>
      <title>Re: PA-220 Slow Response time connecting over ipsec tunnel to AWS.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-220-slow-response-time-connecting-over-ipsec-tunnel-to-aws/m-p/537751#M110432</link>
      <description>&lt;P&gt;Tunnel interfaces have IPs configured and ping permitted on both sides?&lt;/P&gt;
&lt;P&gt;If not then&amp;nbsp;&lt;SPAN&gt;PMTUD packets might not be passed through and this can cause slowness.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;MSS helps only with TCP but UDP sill needs to learn MTU limit the hard way.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 05 Apr 2023 15:01:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-220-slow-response-time-connecting-over-ipsec-tunnel-to-aws/m-p/537751#M110432</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2023-04-05T15:01:12Z</dc:date>
    </item>
    <item>
      <title>Re: PA-220 Slow Response time connecting over ipsec tunnel to AWS.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-220-slow-response-time-connecting-over-ipsec-tunnel-to-aws/m-p/537815#M110449</link>
      <description>&lt;P&gt;Yeah I did look at the AWS tunnel settings, but I noticed they only had MTU, not MSS. IFor the tunnels the Management Profile set to None, MTU is empty.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 05 Apr 2023 22:58:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-220-slow-response-time-connecting-over-ipsec-tunnel-to-aws/m-p/537815#M110449</guid>
      <dc:creator>FMA-Admin</dc:creator>
      <dc:date>2023-04-05T22:58:43Z</dc:date>
    </item>
    <item>
      <title>Re: PA-220 Slow Response time connecting over ipsec tunnel to AWS.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-220-slow-response-time-connecting-over-ipsec-tunnel-to-aws/m-p/538000#M110473</link>
      <description>&lt;P&gt;Take a look at this KB&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/blogs/tcp-mss-adjustments-updated-february-2023/ba-p/156881" target="_blank"&gt;https://live.paloaltonetworks.com/t5/blogs/tcp-mss-adjustments-updated-february-2023/ba-p/156881&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also according to link below '&lt;SPAN&gt;For TCP traffic over IPSec Tunnel, the Palo Alto Networks firewall will automatically adjust the TCP MSS in the three-way handshake.'&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClW3CAK" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClW3CAK&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So instead of playing around with MTU and MSS confirm that&amp;nbsp;&lt;SPAN&gt;PMTUD&amp;nbsp;packets are utilized.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I am pretty sure you need to have management profile that permits ping on tunnel interface for that.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 07 Apr 2023 14:28:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-220-slow-response-time-connecting-over-ipsec-tunnel-to-aws/m-p/538000#M110473</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2023-04-07T14:28:09Z</dc:date>
    </item>
  </channel>
</rss>

