<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Global Protect IPSec/SSL in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-ipsec-ssl/m-p/208497#M61037</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am using a pa-3050 running 7.1.10 and it is pretty consistant that the tests come back with I would say between 10-12 mbps down if on a SSL tunnel. I've done tests on 10, 50, and 100 bandwidth pipes and its always around that range.&lt;/P&gt;</description>
    <pubDate>Mon, 02 Apr 2018 23:32:40 GMT</pubDate>
    <dc:creator>Justin.Abendroth</dc:creator>
    <dc:date>2018-04-02T23:32:40Z</dc:date>
    <item>
      <title>Global Protect IPSec/SSL</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-ipsec-ssl/m-p/208484#M61034</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If global protect fails to establish a IPSec tunnel and uses SSL instead, does it attempt to switch tunnel types if it sees it can do a IPSec tunnel or will it keep it's current tunnel type until the GP client get's refreshed and sees what connection it can establish?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The reason I ask is because Global Protect is extremly slow when it uses SSL as it's tunnel. I can do a speed test on a 100 mbps line using IPSec and get near perfect speeds, but if the tunnel is SSL, my tests hang around 10 mbps down.&lt;/P&gt;</description>
      <pubDate>Mon, 02 Apr 2018 21:43:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-ipsec-ssl/m-p/208484#M61034</guid>
      <dc:creator>Justin.Abendroth</dc:creator>
      <dc:date>2018-04-02T21:43:49Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect IPSec/SSL</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-ipsec-ssl/m-p/208496#M61036</link>
      <description>&lt;P&gt;What hardware are you using (GP gateway)? Is it 10mbps constantly or more an up and down with peaks at 10mbps?&lt;/P&gt;</description>
      <pubDate>Mon, 02 Apr 2018 23:05:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-ipsec-ssl/m-p/208496#M61036</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2018-04-02T23:05:53Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect IPSec/SSL</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-ipsec-ssl/m-p/208497#M61037</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am using a pa-3050 running 7.1.10 and it is pretty consistant that the tests come back with I would say between 10-12 mbps down if on a SSL tunnel. I've done tests on 10, 50, and 100 bandwidth pipes and its always around that range.&lt;/P&gt;</description>
      <pubDate>Mon, 02 Apr 2018 23:32:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-ipsec-ssl/m-p/208497#M61037</guid>
      <dc:creator>Justin.Abendroth</dc:creator>
      <dc:date>2018-04-02T23:32:40Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect IPSec/SSL</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-ipsec-ssl/m-p/208498#M61038</link>
      <description>&lt;P&gt;But regarding your question: no, there is no automatic fallback to IPSec. After a network change or a manual network rediscovery where the connection needs to be reestablished, GP will try again first wirh IPsec. And may be even there GP stays with TLS, if you have configured a reconnect time where GP client is allowed to reconnect to an existing session.&lt;/P&gt;</description>
      <pubDate>Mon, 02 Apr 2018 23:34:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-ipsec-ssl/m-p/208498#M61038</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2018-04-02T23:34:28Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect IPSec/SSL</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-ipsec-ssl/m-p/208499#M61039</link>
      <description>&lt;P&gt;It's not very likely, because you tested with different internet access, but it still might be related to MTU mismatch issues. TLS connection don't like fragmentation.&amp;nbsp;&lt;/P&gt;&lt;P&gt;But there are quite a few other things that are part of the game here:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;PAN-OS 7.1.10: maybe a bug with the decryption performance?&lt;/LI&gt;&lt;LI&gt;GP Agent version: versions 4.0.3/4/5 has a bug where fragmented udp packets were dropped - may be related if you use chrome for download tests that was connection to the servers with TLS over UDP&lt;/LI&gt;&lt;LI&gt;MTU/MSS mismatch issues&lt;/LI&gt;&lt;LI&gt;Do you use the same firewall also for other things? Like TLS forward proxy or TLS inbound inspection, so the firewall was already busy with other things when you did your test&lt;/LI&gt;&lt;/UL&gt;</description>
      <pubDate>Mon, 02 Apr 2018 23:45:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-ipsec-ssl/m-p/208499#M61039</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2018-04-02T23:45:10Z</dc:date>
    </item>
  </channel>
</rss>

