<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VPN Performance Problem in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-performance-problem/m-p/47844#M35167</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Certainly seems like a bug that will need to be addressed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What do the cpu stats look like when the nat is enabled?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm guessing there is some kind of bug interaction between nat and some other portion of the configuration.&amp;nbsp; So you may end up with an option to keep the nat and change some other portion of the config to get past the bug until it is patched.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sat, 21 Jun 2014 12:17:03 GMT</pubDate>
    <dc:creator>pulukas</dc:creator>
    <dc:date>2014-06-21T12:17:03Z</dc:date>
    <item>
      <title>VPN Performance Problem</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-performance-problem/m-p/47843#M35166</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Just wanted to all let you know about a VPN performance issue we have with one of our customers.&lt;/P&gt;&lt;P&gt;The customers is running an IPSec Site2Site Tunnel to a third party company (Cisco Device). They have a PA-5020 Cluster (5.0.12) and the Tunnel link is providing 1Gb/s throughput. Now all was working fine until the customer added a source NAT for the traffic entering the tunnel. The throughput went down from around 900Mb/s to 300Mb/s. &lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;Disabling that particular NAT restores full throughput again. Case is open, so far there are no config issues, but still waiting for further findings.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Has anyone observed such a performance impact when configuring a source NAT in a VPN Tunnel ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 20 Jun 2014 06:57:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-performance-problem/m-p/47843#M35166</guid>
      <dc:creator>gafrol</dc:creator>
      <dc:date>2014-06-20T06:57:15Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Performance Problem</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-performance-problem/m-p/47844#M35167</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Certainly seems like a bug that will need to be addressed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What do the cpu stats look like when the nat is enabled?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm guessing there is some kind of bug interaction between nat and some other portion of the configuration.&amp;nbsp; So you may end up with an option to keep the nat and change some other portion of the config to get past the bug until it is patched.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 21 Jun 2014 12:17:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-performance-problem/m-p/47844#M35167</guid>
      <dc:creator>pulukas</dc:creator>
      <dc:date>2014-06-21T12:17:03Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Performance Problem</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-performance-problem/m-p/47845#M35168</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Nothing abnormal on the CPU load. Cleartext source NAT does not suffer from this performance hit, only source NAT within a tunnel seems to create the problem.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 23 Jun 2014 06:57:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-performance-problem/m-p/47845#M35168</guid>
      <dc:creator>gafrol</dc:creator>
      <dc:date>2014-06-23T06:57:06Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Performance Problem</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-performance-problem/m-p/47846#M35169</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P dir="ltr" style="color: #222222; font-family: arial, sans-serif; font-size: 12.727272033691406px;"&gt;Are your NAT rules sufficiently wide to include ICMP traffic? &lt;/P&gt;&lt;P dir="ltr" style="color: #222222; font-family: arial, sans-serif; font-size: 12.727272033691406px;"&gt;&lt;/P&gt;&lt;P dir="ltr" style="color: #222222; font-family: arial, sans-serif; font-size: 12.727272033691406px;"&gt;The MTU across the tunnel will be lower than normal.&amp;nbsp; Perhaps without the NAT, MTU discovery (using ICMP) is working - lowering the MSS of the TCP sessions across the tunnel.&amp;nbsp; If the NAT doesn't include ICMP traffic, MTU discovery will be broken and your traffic flow rate will suffer greatly...&lt;/P&gt;&lt;P dir="ltr" style="color: #222222; font-family: arial, sans-serif; font-size: 12.727272033691406px;"&gt;&lt;/P&gt;&lt;P dir="ltr" style="color: #222222; font-family: arial, sans-serif; font-size: 12.727272033691406px;"&gt;I'd ensure the NAT rule has no service component so it is just acting on the IP addresses at each end of the link (and perhaps the in/out interfaces).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 23 Jun 2014 08:06:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-performance-problem/m-p/47846#M35169</guid>
      <dc:creator>ajbool</dc:creator>
      <dc:date>2014-06-23T08:06:10Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Performance Problem</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-performance-problem/m-p/47847#M35170</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote" modifiedtitle="true"&gt;
&lt;P&gt;Are your NAT rules sufficiently wide to include ICMP traffic? &lt;/P&gt;
&lt;P dir="ltr"&gt;&lt;/P&gt;
&lt;/PRE&gt;&lt;P&gt;Yes, we usually don't use service restrictions in the NAT, this is done in the security rules.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 23 Jun 2014 08:28:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-performance-problem/m-p/47847#M35170</guid>
      <dc:creator>gafrol</dc:creator>
      <dc:date>2014-06-23T08:28:44Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Performance Problem</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-performance-problem/m-p/47848#M35171</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I saw a case with the same issue which is still in the research phase. You should open a case too. Maybe this will speed up the process if you can provide more data.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 23 Jun 2014 09:00:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-performance-problem/m-p/47848#M35171</guid>
      <dc:creator>Wenar</dc:creator>
      <dc:date>2014-06-23T09:00:18Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Performance Problem</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-performance-problem/m-p/47849#M35172</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Case is open since one week&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 23 Jun 2014 09:52:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-performance-problem/m-p/47849#M35172</guid>
      <dc:creator>gafrol</dc:creator>
      <dc:date>2014-06-23T09:52:56Z</dc:date>
    </item>
  </channel>
</rss>

