<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Slowness over VPN in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/slowness-over-vpn/m-p/19973#M14551</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;Hello Sir,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;I would request you to try with below mentioned options, in order to improve the performance through the VPN tunnel.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;1. Can you verify what Encryption Standards are being used?&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;Group 5 &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;( &lt;/SPAN&gt;&lt;/SPAN&gt;Asymmetric Key Encryption&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt; )&lt;/SPAN&gt;&lt;/SPAN&gt; and AES &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;( &lt;/SPAN&gt;&lt;/SPAN&gt;Symmetric &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;key&lt;/SPAN&gt;&lt;/SPAN&gt; Encryption&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt; )&lt;/SPAN&gt;&lt;/SPAN&gt; Standards are more CPU extensive than Group-2 or 3DES. Does the performance improve with Group 2 and 3DES?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;2) Slowness of Transfers across VPN tunnels are usually seen when the ESP packets are either fragmented, or when the packets themselves come out of sequence before they are being encrypted. &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;( &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;the&lt;/SPAN&gt;&lt;/SPAN&gt; firewall performs checks for the TCP &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;anomolies&lt;/SPAN&gt;&lt;/SPAN&gt; before it can encrypt these packets in the ESP headers&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt; )&lt;/SPAN&gt;&lt;/SPAN&gt;. Please check for any asymmetric routing issues.&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;3) If the performance is still not that great, an alternative&amp;nbsp; to create a custom app for required traffic, and use it under an app override. With this setting, we bypass the signature check for this traffic, and hence can expect better results. Refer to the below doc for configuring Application override for certain traffic.&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-1071"&gt;How to Create an Application Override Policy&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;NOTE: As you said before, after enabling "Adjust MSS" you lost the connectivity through primary ISP, do you have an alternate path to troubleshoot &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;( &lt;/SPAN&gt;&lt;/SPAN&gt;not through ISP-1 or ISP-2) which will not close the SSH or GUI session at least.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 03 Feb 2014 19:37:58 GMT</pubDate>
    <dc:creator>HULK</dc:creator>
    <dc:date>2014-02-03T19:37:58Z</dc:date>
    <item>
      <title>Slowness over VPN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/slowness-over-vpn/m-p/19972#M14550</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I just modified a PA-200 in our remote office to use two internet connections and two VPN connections for fail-over. The tunnels are up and are passing traffic fine for me, however users in that office are complaining about slowness over the VPN. There is zero packet loss over the tunnel and connectivity to the internet is just fine, from what I am told. Other discussions on this site have suggested enabling TCP MSS (which I did on the WAN interfaces) but I completely loss connectivity to those interfaces when I did. I had to get access to the device again via the secondary ISP. I try to access the trust interface of this device over the tunnel and the Web UI attempts to load (displays connecting in the tab and immediately changes to Login) but it actually never loads, the page is just plain white. SSH access to this same interface will work better but seems to eventually die. I seem to have better success accessing the firewall via the WAN interface via UI or SSH. This definitely seems to be an issue with the VPN tunnel(s). Session ID details from the CLI show all traffic is being processed by the correct interfaces, PBFs, tunnels, etc. All traffic is traversing a newly configured ISP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here are my PBF rules:&lt;/P&gt;&lt;P&gt;&lt;IMG alt="Screen Shot 2014-02-03 at 9.04.07 AM.png" class="jive-image" height="38" src="https://live.paloaltonetworks.com/legacyfs/online/11407_Screen Shot 2014-02-03 at 9.04.07 AM.png" style="width: 1385.88px; height: 38px;" width="1386" /&gt;&lt;/P&gt;&lt;P&gt;The first is a rule to send traffic over the primary ISP and VPN, the second is a backup ISP and VPN. All traffic according to the firewall is traversing tunnel.10, as it should be.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any help would be appreciated!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 03 Feb 2014 16:16:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/slowness-over-vpn/m-p/19972#M14550</guid>
      <dc:creator>mario11584</dc:creator>
      <dc:date>2014-02-03T16:16:54Z</dc:date>
    </item>
    <item>
      <title>Re: Slowness over VPN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/slowness-over-vpn/m-p/19973#M14551</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;Hello Sir,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;I would request you to try with below mentioned options, in order to improve the performance through the VPN tunnel.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;1. Can you verify what Encryption Standards are being used?&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;Group 5 &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;( &lt;/SPAN&gt;&lt;/SPAN&gt;Asymmetric Key Encryption&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt; )&lt;/SPAN&gt;&lt;/SPAN&gt; and AES &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;( &lt;/SPAN&gt;&lt;/SPAN&gt;Symmetric &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;key&lt;/SPAN&gt;&lt;/SPAN&gt; Encryption&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt; )&lt;/SPAN&gt;&lt;/SPAN&gt; Standards are more CPU extensive than Group-2 or 3DES. Does the performance improve with Group 2 and 3DES?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;2) Slowness of Transfers across VPN tunnels are usually seen when the ESP packets are either fragmented, or when the packets themselves come out of sequence before they are being encrypted. &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;( &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;the&lt;/SPAN&gt;&lt;/SPAN&gt; firewall performs checks for the TCP &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;anomolies&lt;/SPAN&gt;&lt;/SPAN&gt; before it can encrypt these packets in the ESP headers&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt; )&lt;/SPAN&gt;&lt;/SPAN&gt;. Please check for any asymmetric routing issues.&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;3) If the performance is still not that great, an alternative&amp;nbsp; to create a custom app for required traffic, and use it under an app override. With this setting, we bypass the signature check for this traffic, and hence can expect better results. Refer to the below doc for configuring Application override for certain traffic.&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-1071"&gt;How to Create an Application Override Policy&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;NOTE: As you said before, after enabling "Adjust MSS" you lost the connectivity through primary ISP, do you have an alternate path to troubleshoot &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;( &lt;/SPAN&gt;&lt;/SPAN&gt;not through ISP-1 or ISP-2) which will not close the SSH or GUI session at least.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 03 Feb 2014 19:37:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/slowness-over-vpn/m-p/19973#M14551</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-02-03T19:37:58Z</dc:date>
    </item>
    <item>
      <title>Re: Slowness over VPN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/slowness-over-vpn/m-p/19974#M14552</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I would say: "Define slowness"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can have great bandwidth throughput, but a roundtrip response time to your DNS servers be very slow. The perceived behavior is slowness in both scenarios. You can also have great performing applications, and applications that behave poorly (Samba file transfers are known to be slow, and they require some tune-up on the firewall).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would troubleshoot such slowness in two ways:&lt;/P&gt;&lt;P&gt;Deploy iperf on both ends of the tunnel and run a TCP test with -P 10 to measure bandwidth throughput.&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.slashroot.in/iperf-how-test-network-speedperformancebandwidth" title="http://www.slashroot.in/iperf-how-test-network-speedperformancebandwidth"&gt;http://www.slashroot.in/iperf-how-test-network-speedperformancebandwidth&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can use tools like NetMeter on the endpoints or &lt;A href="https://live.paloaltonetworks.com/docs/DOC-7404"&gt;Graphic Traffic Monitoring for Interfaces - QoS Statistics&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Check how users reach their DNS servers. If you are forcing everyone to go to your central office for DNS resolution, and you are in the opposite side of the globe, you are injecting huge delays in DNS responses.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mariano.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 22 Aug 2014 21:35:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/slowness-over-vpn/m-p/19974#M14552</guid>
      <dc:creator>mivaldi</dc:creator>
      <dc:date>2014-08-22T21:35:24Z</dc:date>
    </item>
  </channel>
</rss>

