<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: iRe: Limitation IPsec VPN performance in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/limitation-ipsec-vpn-performance/m-p/77430#M42596</link>
    <description>&lt;P&gt;Palo Alto uses small 64k packet size when they put together their datasheet (worst case cenario).&lt;/P&gt;
&lt;P&gt;Many competitors use large packets (best case cenario) in their datasheets.&lt;/P&gt;
&lt;P&gt;For that reason you often get better performance with Palo than advertised.&lt;/P&gt;</description>
    <pubDate>Tue, 03 May 2016 16:19:40 GMT</pubDate>
    <dc:creator>Raido_Rattameister</dc:creator>
    <dc:date>2016-05-03T16:19:40Z</dc:date>
    <item>
      <title>Limitation IPsec VPN performance</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/limitation-ipsec-vpn-performance/m-p/77347#M42574</link>
      <description>&lt;P&gt;&lt;SPAN class=""&gt;&lt;SPAN&gt;Hello&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class=""&gt;&lt;SPAN&gt;I have 2&lt;/SPAN&gt; &lt;SPAN&gt;PA-&lt;/SPAN&gt;&lt;SPAN&gt;500 in&lt;/SPAN&gt; &lt;SPAN&gt;active&lt;/SPAN&gt;&lt;SPAN&gt;-&lt;/SPAN&gt;passive mode (Pan-os 6.1.0)&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;In&lt;/SPAN&gt; &lt;SPAN&gt;the model specification&lt;/SPAN&gt; &lt;SPAN&gt;PA&lt;/SPAN&gt;&lt;SPAN&gt;-500&lt;/SPAN&gt; &lt;SPAN&gt;shows that "&lt;/SPAN&gt;&lt;SPAN&gt;IPsec&lt;/SPAN&gt; &lt;SPAN&gt;VPN&lt;/SPAN&gt; &lt;SPAN&gt;performance&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt; &lt;SPAN&gt;is 50&lt;/SPAN&gt; &lt;SPAN&gt;Mbps&lt;/SPAN&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;I want to make &lt;SPAN&gt;an IPSec VPN tunnel&lt;/SPAN&gt; &lt;SPAN&gt;with a&lt;/SPAN&gt; &lt;SPAN&gt;cloud provider&lt;/SPAN&gt;&lt;SPAN&gt;.&lt;/SPAN&gt; &lt;SPAN&gt;The speed that&lt;/SPAN&gt; &lt;SPAN&gt;gives me&lt;/SPAN&gt; &lt;SPAN&gt;supplier&lt;/SPAN&gt; &lt;SPAN&gt;for&lt;/SPAN&gt; &lt;SPAN&gt;the tunnel&lt;/SPAN&gt; &lt;SPAN&gt;is 100&lt;/SPAN&gt; &lt;SPAN&gt;Mpbs&lt;/SPAN&gt; &lt;SPAN&gt;guaranteed&lt;/SPAN&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Does this mean that&lt;/SPAN&gt; &lt;SPAN&gt;my connection with&lt;/SPAN&gt; &lt;SPAN&gt;cloud provider may&lt;/SPAN&gt; &lt;SPAN&gt;not exceed&lt;/SPAN&gt; &lt;SPAN&gt;50&lt;/SPAN&gt; Mbps&lt;SPAN&gt;?&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Can you&lt;/SPAN&gt; &lt;SPAN&gt;clarify&lt;/SPAN&gt; &lt;SPAN&gt;a little more&lt;/SPAN&gt; &lt;SPAN&gt;what it means "IPsec VPN performance"? &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class=""&gt;&lt;SPAN&gt;Thank you&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 02 May 2016 10:55:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/limitation-ipsec-vpn-performance/m-p/77347#M42574</guid>
      <dc:creator>Sistemas_SanLucar</dc:creator>
      <dc:date>2016-05-02T10:55:18Z</dc:date>
    </item>
    <item>
      <title>Re: Limitation IPsec VPN performance</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/limitation-ipsec-vpn-performance/m-p/77348#M42575</link>
      <description>&lt;P&gt;Basically yes if spec sheet tells you that device max IPSec performance is 50Mbit then you can get 50Mbit connection.&lt;/P&gt;
&lt;P&gt;What you can try is to configure multiple proxy id's.&lt;/P&gt;
&lt;P&gt;Every proxy id mapping will mean seperate tunnel between endpoints and as seperate tunnels can be load balanced to different cpu's in Palo then it might give slightly better performance.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 02 May 2016 11:27:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/limitation-ipsec-vpn-performance/m-p/77348#M42575</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2016-05-02T11:27:25Z</dc:date>
    </item>
    <item>
      <title>Re: Limitation IPsec VPN performance</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/limitation-ipsec-vpn-performance/m-p/77373#M42581</link>
      <description>&lt;P&gt;Thanks for your reply.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If we change Pa-500 from active-pasive to active-active ,, it could balance the tunnel and therefore could gain a better Ipsec performance ?balance the tunnel and therefore gains Ipsec performance ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you&lt;/P&gt;</description>
      <pubDate>Mon, 02 May 2016 19:23:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/limitation-ipsec-vpn-performance/m-p/77373#M42581</guid>
      <dc:creator>Sistemas_SanLucar</dc:creator>
      <dc:date>2016-05-02T19:23:19Z</dc:date>
    </item>
    <item>
      <title>Re: Limitation IPsec VPN performance</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/limitation-ipsec-vpn-performance/m-p/77377#M42584</link>
      <description>&lt;P&gt;Palo Alto has route based vpn.&lt;/P&gt;
&lt;P&gt;It means it decides based on routing table if packet should be sent into tunnel.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you have vpn to device that uses policy based vpn then other side decides based on policy (not routing table) if packet should be sent into tunnel.&lt;/P&gt;
&lt;P&gt;Cisco call those policies encryption domains. Palo calls same thing Proxy id.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You don't need to configure Proxy id if vpn is between 2 Palos but you can still use them.&lt;/P&gt;
&lt;P&gt;If you add multiple proxy id's then every proxy id means seperate vpn tunnel. One tunnel is processed by single cpu but if you spread traffic to multiple tunnels then they can be scheduled to diferent cpu's in Palo and you can get better performance.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It has nothing to do with A/P and A/A high availability.&lt;/P&gt;
&lt;P&gt;Don't change HA setup without good planning.&lt;/P&gt;
&lt;P&gt;If you have bad planning then A/A HA has lower performance than A/P.&lt;/P&gt;</description>
      <pubDate>Mon, 02 May 2016 22:23:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/limitation-ipsec-vpn-performance/m-p/77377#M42584</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2016-05-02T22:23:46Z</dc:date>
    </item>
    <item>
      <title>Re: Limitation IPsec VPN performance</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/limitation-ipsec-vpn-performance/m-p/77386#M42585</link>
      <description>&lt;P&gt;PA devices usualy perform really well regarding troughput. Have you tested if you can maybe get more than 50 Mbps in current setp? &amp;nbsp;Will you really generate that much traffic constantly?&lt;/P&gt;
&lt;P&gt;Another thing to consider is that IPSEC traffic has some overhead as well, so on 100 Mbps link you will never get 100 Mbps IPSEC throughput.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;A/A should theoretically give you more throughput. But PA doesn't recommend using A/A to increase thrroughput.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 03 May 2016 06:16:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/limitation-ipsec-vpn-performance/m-p/77386#M42585</guid>
      <dc:creator>santonic</dc:creator>
      <dc:date>2016-05-03T06:16:41Z</dc:date>
    </item>
    <item>
      <title>iRe: Limitation IPsec VPN performance</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/limitation-ipsec-vpn-performance/m-p/77424#M42595</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class=""&gt;&lt;SPAN&gt;I&lt;/SPAN&gt; just saw on &lt;SPAN&gt;Cacti&lt;/SPAN&gt; &lt;SPAN&gt;graphs&lt;/SPAN&gt; &lt;SPAN&gt;that we are reaching&lt;/SPAN&gt; &lt;SPAN&gt;with our supplier&lt;/SPAN&gt; &lt;SPAN&gt;cloud&lt;/SPAN&gt; &lt;SPAN&gt;an output of&lt;/SPAN&gt; &lt;SPAN&gt;80&lt;/SPAN&gt; &lt;SPAN&gt;mbps.&lt;/SPAN&gt; &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class=""&gt;Our line &lt;SPAN&gt;is 80&lt;/SPAN&gt; &lt;SPAN&gt;mbps simétric.&lt;BR /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class=""&gt;&lt;BR /&gt;&lt;SPAN&gt;So&lt;/SPAN&gt; &lt;SPAN&gt;I can not&lt;/SPAN&gt; finish to understand &lt;SPAN&gt;because it brings&lt;/SPAN&gt; &lt;SPAN&gt;more&lt;/SPAN&gt; &lt;SPAN&gt;performance if&lt;/SPAN&gt; it is &lt;SPAN&gt;limited to&lt;/SPAN&gt; &lt;SPAN&gt;50Mbps&lt;/SPAN&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class=""&gt;&lt;SPAN&gt;The&lt;/SPAN&gt; &lt;SPAN&gt;tunnel is&lt;/SPAN&gt; &lt;SPAN&gt;DES&lt;/SPAN&gt; encryption&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Can you&lt;/SPAN&gt; &lt;SPAN&gt;clarify this&lt;/SPAN&gt;&lt;SPAN&gt;?&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Thank you&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 03 May 2016 15:30:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/limitation-ipsec-vpn-performance/m-p/77424#M42595</guid>
      <dc:creator>Sistemas_SanLucar</dc:creator>
      <dc:date>2016-05-03T15:30:54Z</dc:date>
    </item>
    <item>
      <title>Re: iRe: Limitation IPsec VPN performance</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/limitation-ipsec-vpn-performance/m-p/77430#M42596</link>
      <description>&lt;P&gt;Palo Alto uses small 64k packet size when they put together their datasheet (worst case cenario).&lt;/P&gt;
&lt;P&gt;Many competitors use large packets (best case cenario) in their datasheets.&lt;/P&gt;
&lt;P&gt;For that reason you often get better performance with Palo than advertised.&lt;/P&gt;</description>
      <pubDate>Tue, 03 May 2016 16:19:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/limitation-ipsec-vpn-performance/m-p/77430#M42596</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2016-05-03T16:19:40Z</dc:date>
    </item>
    <item>
      <title>Re: iRe: Limitation IPsec VPN performance</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/limitation-ipsec-vpn-performance/m-p/77432#M42597</link>
      <description>&lt;P&gt;By the way DES is not secure to use nowadays.&lt;/P&gt;</description>
      <pubDate>Tue, 03 May 2016 16:20:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/limitation-ipsec-vpn-performance/m-p/77432#M42597</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2016-05-03T16:20:38Z</dc:date>
    </item>
    <item>
      <title>Re: iRe: Limitation IPsec VPN performance</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/limitation-ipsec-vpn-performance/m-p/77540#M42634</link>
      <description>&lt;P&gt;Declared throughput is not limit. It's guaranteed.&lt;/P&gt;</description>
      <pubDate>Thu, 05 May 2016 07:28:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/limitation-ipsec-vpn-performance/m-p/77540#M42634</guid>
      <dc:creator>santonic</dc:creator>
      <dc:date>2016-05-05T07:28:12Z</dc:date>
    </item>
  </channel>
</rss>

