<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Recommended MTU for GlobalProtect Gateway in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/recommended-mtu-for-globalprotect-gateway/m-p/155687#M51174</link>
    <description>&lt;P&gt;You have 0.0.0.0/0 route so all traffic goes into tunnel when GP is connected?&lt;/P&gt;&lt;P&gt;I have not changed MTU in my environment so using default.&lt;/P&gt;&lt;P&gt;Currently at home with 20Mbit down and I get same result (+/- 1Mbit) with and without GlobalProtect (no split tunneling, using 0.0.0.0/0 route in my GP config).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Test with&amp;nbsp;&lt;A href="http://www.speedtest.net" target="_blank"&gt;http://www.speedtest.net&lt;/A&gt;&lt;/P&gt;&lt;P&gt;What is speed and latency when GP is on and when GP is off?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any QoS in use?&lt;/P&gt;</description>
    <pubDate>Tue, 09 May 2017 12:55:14 GMT</pubDate>
    <dc:creator>Raido_Rattameister</dc:creator>
    <dc:date>2017-05-09T12:55:14Z</dc:date>
    <item>
      <title>Recommended MTU for GlobalProtect Gateway</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/recommended-mtu-for-globalprotect-gateway/m-p/155641#M51156</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We’re experiencing slowness from global connect clients located offsite back to firewall (i.e. 5MBps). Without the VPN client, the user can get up to 60MBps.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What is the recommended MTU settings for GlobalProtect Gateway/interface should be set at? Our Ethernet interface(1/3) MTU where gateway terminates in DMZ is set at 1350 and the tunnel.11 is set to 1400. Does this need to be the same?&lt;/P&gt;&lt;P&gt;I have already checked the KB below.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Management-Articles/How-to-Improve-Performance-for-IPSec-Traffic/ta-p/53301" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Management-Articles/How-to-Improve-Performance-for-IPSec-Traffic/ta-p/53301&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;</description>
      <pubDate>Tue, 09 May 2017 02:52:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/recommended-mtu-for-globalprotect-gateway/m-p/155641#M51156</guid>
      <dc:creator>Farzana</dc:creator>
      <dc:date>2017-05-09T02:52:26Z</dc:date>
    </item>
    <item>
      <title>Re: Recommended MTU for GlobalProtect Gateway</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/recommended-mtu-for-globalprotect-gateway/m-p/155642#M51157</link>
      <description>&lt;P&gt;Open GlobalProtect client.&lt;/P&gt;&lt;P&gt;Go to Details tab.&lt;/P&gt;&lt;P&gt;Is protocol SSL or IPSec?&lt;/P&gt;&lt;P&gt;If SSL then check if you are blocking incoming UDP port 4501 towards GlobalProtect Gateway.&lt;/P&gt;&lt;P&gt;SSL runs over TCP.&lt;/P&gt;&lt;P&gt;IPSec runs over UDP and avoids TCP meltdown issue.&lt;/P&gt;</description>
      <pubDate>Tue, 09 May 2017 02:56:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/recommended-mtu-for-globalprotect-gateway/m-p/155642#M51157</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2017-05-09T02:56:20Z</dc:date>
    </item>
    <item>
      <title>Re: Recommended MTU for GlobalProtect Gateway</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/recommended-mtu-for-globalprotect-gateway/m-p/155644#M51159</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Checked all that you mentioned is fine. C&lt;SPAN&gt;lients connecting using IPSEC.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 09 May 2017 04:21:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/recommended-mtu-for-globalprotect-gateway/m-p/155644#M51159</guid>
      <dc:creator>Farzana</dc:creator>
      <dc:date>2017-05-09T04:21:26Z</dc:date>
    </item>
    <item>
      <title>Re: Recommended MTU for GlobalProtect Gateway</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/recommended-mtu-for-globalprotect-gateway/m-p/155645#M51160</link>
      <description>&lt;P&gt;How do you measure speed?&lt;BR /&gt;Do you have public website in your environment you could place some big file and try to download it without GP over public internet and with GP connected over tunnel?&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 09 May 2017 04:37:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/recommended-mtu-for-globalprotect-gateway/m-p/155645#M51160</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2017-05-09T04:37:10Z</dc:date>
    </item>
    <item>
      <title>Re: Recommended MTU for GlobalProtect Gateway</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/recommended-mtu-for-globalprotect-gateway/m-p/155651#M51163</link>
      <description>&lt;P&gt;Hi Raido,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Yes, we have a FTP service in the DMZ on same interface and speed is fine.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;All we really want to know is what should the MTU settings on the tunnel vs interface be set at?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;We have tried setting interface to 1360, tunnel MTU to 1400 and select Adjust TCP MSS.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Getting 10MB down/10MB up. Without VPN we’re getting 40MB down/27MB up. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Is this what we should be seeing for GP VPN?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 09 May 2017 06:56:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/recommended-mtu-for-globalprotect-gateway/m-p/155651#M51163</guid>
      <dc:creator>Farzana</dc:creator>
      <dc:date>2017-05-09T06:56:04Z</dc:date>
    </item>
    <item>
      <title>Re: Recommended MTU for GlobalProtect Gateway</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/recommended-mtu-for-globalprotect-gateway/m-p/155687#M51174</link>
      <description>&lt;P&gt;You have 0.0.0.0/0 route so all traffic goes into tunnel when GP is connected?&lt;/P&gt;&lt;P&gt;I have not changed MTU in my environment so using default.&lt;/P&gt;&lt;P&gt;Currently at home with 20Mbit down and I get same result (+/- 1Mbit) with and without GlobalProtect (no split tunneling, using 0.0.0.0/0 route in my GP config).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Test with&amp;nbsp;&lt;A href="http://www.speedtest.net" target="_blank"&gt;http://www.speedtest.net&lt;/A&gt;&lt;/P&gt;&lt;P&gt;What is speed and latency when GP is on and when GP is off?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any QoS in use?&lt;/P&gt;</description>
      <pubDate>Tue, 09 May 2017 12:55:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/recommended-mtu-for-globalprotect-gateway/m-p/155687#M51174</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2017-05-09T12:55:14Z</dc:date>
    </item>
  </channel>
</rss>

