<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Slow transferspeed over IPSec against ASA5510 in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/slow-transferspeed-over-ipsec-against-asa5510/m-p/40690#M29881</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;a) No luck with the "Adjust TCP MSS" Option, Running Group 2 and 3DES&lt;/P&gt;&lt;P&gt;b) I'll look for asymmetrical routes, but have not been able to see any so far....&lt;/P&gt;&lt;P&gt;c) no QoS applied&lt;/P&gt;&lt;P&gt;d) Inspection on this traffic was already off&lt;/P&gt;&lt;P&gt;e) I'll try this and see if it helps &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://live.paloaltonetworks.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for all suggestions so far &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://live.paloaltonetworks.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 05 Nov 2013 11:09:10 GMT</pubDate>
    <dc:creator>TJ</dc:creator>
    <dc:date>2013-11-05T11:09:10Z</dc:date>
    <item>
      <title>Slow transferspeed over IPSec against ASA5510</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/slow-transferspeed-over-ipsec-against-asa5510/m-p/40683#M29874</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;One of our customer has a Cisco ASA 5510.&lt;/P&gt;&lt;P&gt;We have successfully created a IPSec tunnel and traffic flows both ways, but when trying to transfer a file, the speed caps at ~300KB/s, every 4-5 packets is dropped and the latency goes from ~3ms to 90ms.&lt;/P&gt;&lt;P&gt;Both locations has a 100/100Mbit/s access.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any good ideas? &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://live.paloaltonetworks.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 04 Nov 2013 10:43:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/slow-transferspeed-over-ipsec-against-asa5510/m-p/40683#M29874</guid>
      <dc:creator>TJ</dc:creator>
      <dc:date>2013-11-04T10:43:26Z</dc:date>
    </item>
    <item>
      <title>Re: Slow transferspeed over IPSec against ASA5510</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/slow-transferspeed-over-ipsec-against-asa5510/m-p/40684#M29875</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If the vpn is stable, try to reduce the TCP MSS (value like 1420 should be OK) and test again...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HA&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 04 Nov 2013 14:16:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/slow-transferspeed-over-ipsec-against-asa5510/m-p/40684#M29875</guid>
      <dc:creator>licenselu</dc:creator>
      <dc:date>2013-11-04T14:16:11Z</dc:date>
    </item>
    <item>
      <title>Re: Slow transferspeed over IPSec against ASA5510</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/slow-transferspeed-over-ipsec-against-asa5510/m-p/40685#M29876</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The VPN is stable, but reducing the value to 1420 did not help&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 04 Nov 2013 14:24:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/slow-transferspeed-over-ipsec-against-asa5510/m-p/40685#M29876</guid>
      <dc:creator>TJ</dc:creator>
      <dc:date>2013-11-04T14:24:36Z</dc:date>
    </item>
    <item>
      <title>Re: Slow transferspeed over IPSec against ASA5510</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/slow-transferspeed-over-ipsec-against-asa5510/m-p/40686#M29877</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What veriosn of PAN do You have?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Some people reported on this forum slownest on 5.0.6 and GlobalProtect. Please try to find this topic&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 04 Nov 2013 14:27:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/slow-transferspeed-over-ipsec-against-asa5510/m-p/40686#M29877</guid>
      <dc:creator>_slv_</dc:creator>
      <dc:date>2013-11-04T14:27:12Z</dc:date>
    </item>
    <item>
      <title>Re: Slow transferspeed over IPSec against ASA5510</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/slow-transferspeed-over-ipsec-against-asa5510/m-p/40687#M29878</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Have you tried to enable "Adjust TCP MSS" on the untrust interface of the PA. You will find it under the advanced option on the interface.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 04 Nov 2013 14:53:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/slow-transferspeed-over-ipsec-against-asa5510/m-p/40687#M29878</guid>
      <dc:creator>shasnain</dc:creator>
      <dc:date>2013-11-04T14:53:39Z</dc:date>
    </item>
    <item>
      <title>Re: Slow transferspeed over IPSec against ASA5510</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/slow-transferspeed-over-ipsec-against-asa5510/m-p/40688#M29879</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Here are a couple of options:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;a) If the "Adjust TCP MSS" Option, did not work, can you verify what Encryption Standards are being used?&lt;/P&gt;&lt;P&gt;Group 5 ( Asymmetric Key Encryption ) and AES ( Symmetric key Encryption ) Standards are more CPU extensive than Group-2 or 3DES. Does the performance improve with Group 2 and 3DES?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;b) Slowness of Transfers across VPN tunnels are usually seen when the ESP packets are either fragmented, or when the packets themselves come out of sequence before they are being encrypted. ( the firewall performs checks for the TCP anomolies before it can encrypt these packets in the ESP headers ). Please check for any asymmetric routing issues.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;c) Check if there is any QoS applied for the tunnel traffic that might be rate limiting the tunneled traffic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;d) Applications like SMB and FTP do not get offloaded to the Hardware offloading chip, and all the packets are subjected to signature checks in the dataplane chips ( for any application shifts). If the client and the server are trusted entities, we can disable server response inspection for the rule permitting this traffic:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;Select 'Options' at the far right of the&amp;nbsp; Security policy &amp;amp; check the option for 'Disable Server Response Inspection'. Commit &amp;amp; attempt your download tests. (Though you could probably give this option a test regardless &amp;amp; compare performance)&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;BR /&gt;e) If the performance is still not that great, an alternative to point 'd' is to create a custom app for the SMB and / or FTP traffic, and use it under an app override. With this setting, we bypass the signature check for this traffic, and hence can expect better results. Refer to the below doc for configuring Application override for certain traffic.&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;A _jive_internal="true" href="https://live.paloaltonetworks.com/docs/DOC-1071"&gt;https://live.paloaltonetworks.com/docs/DOC-1071&lt;/A&gt;&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;Hope that helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;BR,&lt;/P&gt;&lt;P&gt;Karthik RP&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 04 Nov 2013 16:31:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/slow-transferspeed-over-ipsec-against-asa5510/m-p/40688#M29879</guid>
      <dc:creator>kprakash</dc:creator>
      <dc:date>2013-11-04T16:31:01Z</dc:date>
    </item>
    <item>
      <title>Re: Slow transferspeed over IPSec against ASA5510</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/slow-transferspeed-over-ipsec-against-asa5510/m-p/40689#M29880</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Tried that, no impact&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 05 Nov 2013 11:06:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/slow-transferspeed-over-ipsec-against-asa5510/m-p/40689#M29880</guid>
      <dc:creator>TJ</dc:creator>
      <dc:date>2013-11-05T11:06:00Z</dc:date>
    </item>
    <item>
      <title>Re: Slow transferspeed over IPSec against ASA5510</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/slow-transferspeed-over-ipsec-against-asa5510/m-p/40690#M29881</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;a) No luck with the "Adjust TCP MSS" Option, Running Group 2 and 3DES&lt;/P&gt;&lt;P&gt;b) I'll look for asymmetrical routes, but have not been able to see any so far....&lt;/P&gt;&lt;P&gt;c) no QoS applied&lt;/P&gt;&lt;P&gt;d) Inspection on this traffic was already off&lt;/P&gt;&lt;P&gt;e) I'll try this and see if it helps &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://live.paloaltonetworks.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for all suggestions so far &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://live.paloaltonetworks.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 05 Nov 2013 11:09:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/slow-transferspeed-over-ipsec-against-asa5510/m-p/40690#M29881</guid>
      <dc:creator>TJ</dc:creator>
      <dc:date>2013-11-05T11:09:10Z</dc:date>
    </item>
  </channel>
</rss>

