<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Restricted tcp flow throughput in a VPN tunnel in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/restricted-tcp-flow-throughput-in-a-vpn-tunnel/m-p/559053#M113389</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;First I would check the MTU settings on the other parts of the network, I've seen something weird like this in the past when jumbo frames were enabled.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
    <pubDate>Thu, 21 Sep 2023 19:52:44 GMT</pubDate>
    <dc:creator>OtakarKlier</dc:creator>
    <dc:date>2023-09-21T19:52:44Z</dc:date>
    <item>
      <title>Restricted tcp flow throughput in a VPN tunnel</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/restricted-tcp-flow-throughput-in-a-vpn-tunnel/m-p/559020#M113386</link>
      <description>&lt;P&gt;Hello all,&lt;/P&gt;
&lt;P&gt;On my firewall I have a VPN tunnel dedicated to VEEAM backup copy to a remote site. I have a throughput problem which is only present with TCP flows.&lt;/P&gt;
&lt;P&gt;I don't have any QOS set on the interface of this tunnel. The flow rule is standard just to make allow.&lt;/P&gt;
&lt;P&gt;The MTU is 1438 and the adjust tcp mss option is set to 40 for IPv4. With UDP flows I have a throughput of 100Mb/s, with TCP flows I'm down to 10 - 15Mb/s.&lt;/P&gt;
&lt;P&gt;How do I know what's restricting the throughput of my TCP flows so much? Thanks&lt;/P&gt;</description>
      <pubDate>Thu, 21 Sep 2023 14:39:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/restricted-tcp-flow-throughput-in-a-vpn-tunnel/m-p/559020#M113386</guid>
      <dc:creator>GuillaumeV</dc:creator>
      <dc:date>2023-09-21T14:39:58Z</dc:date>
    </item>
    <item>
      <title>Re: Restricted tcp flow throughput in a VPN tunnel</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/restricted-tcp-flow-throughput-in-a-vpn-tunnel/m-p/559053#M113389</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;First I would check the MTU settings on the other parts of the network, I've seen something weird like this in the past when jumbo frames were enabled.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Thu, 21 Sep 2023 19:52:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/restricted-tcp-flow-throughput-in-a-vpn-tunnel/m-p/559053#M113389</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2023-09-21T19:52:44Z</dc:date>
    </item>
    <item>
      <title>Re: Restricted tcp flow throughput in a VPN tunnel</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/restricted-tcp-flow-throughput-in-a-vpn-tunnel/m-p/559168#M113410</link>
      <description>&lt;P&gt;Hello,&lt;BR /&gt;So the MTU was defined via tests. We set it to the value that doesn't cause fragmentation.&lt;BR /&gt;None of our ESXIs have JUMBO frames enabled. We would have because we use iscsi but we don't have it enabled. So no problem with JUMBO&lt;/P&gt;</description>
      <pubDate>Fri, 22 Sep 2023 14:05:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/restricted-tcp-flow-throughput-in-a-vpn-tunnel/m-p/559168#M113410</guid>
      <dc:creator>GuillaumeV</dc:creator>
      <dc:date>2023-09-22T14:05:39Z</dc:date>
    </item>
    <item>
      <title>Re: Restricted tcp flow throughput in a VPN tunnel</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/restricted-tcp-flow-throughput-in-a-vpn-tunnel/m-p/559382#M113435</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;Another thing you can try to do is within the policy disable "&lt;SPAN&gt;Disable Server Response Inspection" in the security policy and see if that helps. Dont recommend it for any to/from internet traffic.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Regards,&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 25 Sep 2023 15:01:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/restricted-tcp-flow-throughput-in-a-vpn-tunnel/m-p/559382#M113435</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2023-09-25T15:01:36Z</dc:date>
    </item>
  </channel>
</rss>

