<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic bad vpn connectivity\packet loss ip sec vpn in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/bad-vpn-connectivity-packet-loss-ip-sec-vpn/m-p/36079#M26515</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have configured an fixed IP sec VPN tunell on my PA 500. The tunell comes up OK, and I can ping an traceroute an IP adress on the network I am connectod too, through the vpn tunell. But Packet loss lies between 20 and 40 % running ping tests.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We experience the same thing on both sides of the tunell.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;what can be wrong here, to me it seems like the vpn config is OK, but that it may be a routing or policy issue, but since 60-80% of the packets are actually coming through, then I dont think it is routing or policy either.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;can it be an issue with ARP tables, if so will a reeboot of the firewall help, or should I reboot our ADSL modem\internet connection ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am not familiar with the use of "tunel monitor" - but could it be a solution there ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;knut&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 04 Sep 2013 13:46:05 GMT</pubDate>
    <dc:creator>knutelde</dc:creator>
    <dc:date>2013-09-04T13:46:05Z</dc:date>
    <item>
      <title>bad vpn connectivity\packet loss ip sec vpn</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/bad-vpn-connectivity-packet-loss-ip-sec-vpn/m-p/36079#M26515</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have configured an fixed IP sec VPN tunell on my PA 500. The tunell comes up OK, and I can ping an traceroute an IP adress on the network I am connectod too, through the vpn tunell. But Packet loss lies between 20 and 40 % running ping tests.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We experience the same thing on both sides of the tunell.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;what can be wrong here, to me it seems like the vpn config is OK, but that it may be a routing or policy issue, but since 60-80% of the packets are actually coming through, then I dont think it is routing or policy either.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;can it be an issue with ARP tables, if so will a reeboot of the firewall help, or should I reboot our ADSL modem\internet connection ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am not familiar with the use of "tunel monitor" - but could it be a solution there ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;knut&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 04 Sep 2013 13:46:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/bad-vpn-connectivity-packet-loss-ip-sec-vpn/m-p/36079#M26515</guid>
      <dc:creator>knutelde</dc:creator>
      <dc:date>2013-09-04T13:46:05Z</dc:date>
    </item>
    <item>
      <title>Re: bad vpn connectivity\packet loss ip sec vpn</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/bad-vpn-connectivity-packet-loss-ip-sec-vpn/m-p/36080#M26516</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The following document explains tunnel monitoring and DPD feature on the Palo Alto:&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-1323"&gt;Dead Peer Detection and Tunnel Monitoring&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As far as improving IPsec performance, you can try adjusting TCP MSS value on the interface associated with that IPsec tunnel. Please refer the following document for the same:&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-3839"&gt;How to Improve Performance for IPSEC Traffic in PANOS 4.0 and above.&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that helps!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Kunal Adak&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 04 Sep 2013 15:23:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/bad-vpn-connectivity-packet-loss-ip-sec-vpn/m-p/36080#M26516</guid>
      <dc:creator>kadak</dc:creator>
      <dc:date>2013-09-04T15:23:48Z</dc:date>
    </item>
    <item>
      <title>Re: bad vpn connectivity\packet loss ip sec vpn</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/bad-vpn-connectivity-packet-loss-ip-sec-vpn/m-p/36081#M26517</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thx Kunal, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;it did not solve this case, it was only a matter of old\filled up ARP tables, because a reboot of ISP router and PA 500 made it work, but it is intresting pdfs because I configure these kind of tunells often&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 09 Sep 2013 12:52:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/bad-vpn-connectivity-packet-loss-ip-sec-vpn/m-p/36081#M26517</guid>
      <dc:creator>knutelde</dc:creator>
      <dc:date>2013-09-09T12:52:56Z</dc:date>
    </item>
  </channel>
</rss>

