<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Slow VPN performance in &amp;gt;ONE&amp;lt; direction in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/slow-vpn-performance-in-gt-one-lt-direction/m-p/217932#M63020</link>
    <description>&lt;P&gt;Hello Community,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i have a strange problem regarding VPN.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here is my setup:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;HQ:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- PA3020 vsys2 connects to a 100/100Mbit WAN. (local, stable provider)&lt;/P&gt;&lt;P&gt;- Public IP is configured directly on a interface of the PA&lt;/P&gt;&lt;P&gt;- Speedtest from local network in HQ commits the 100/100Mbit&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Branch:&lt;/P&gt;&lt;P&gt;- PA220 connects to a 50/10Mbit Vodafone WAN&lt;/P&gt;&lt;P&gt;- NAT will be applied on the WAN interface of the PA220, so i dont have to configure routing on the Vodafone box.&lt;/P&gt;&lt;P&gt;- NAT will be applied on the Vodafone box to communicate to the internet&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Because it is not a business line, i have to work with the transfernetwork between Vodafone box an PA220&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- Speedtest for local internetconnection wich passes the PA220 gives me 50/10Mbit - everything is fine.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Problem:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- When i am uploading from Branch to HQ, i get full 10MBIT&lt;/P&gt;&lt;P&gt;- When i am uploading from HQ to Branch, i get a maximum ov 2-5&amp;nbsp; MBIT out of the 50MBit&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What have i tested:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- Different MTU sizes for tunnel and WAN interfaces, from 1500 down to 1260&lt;/P&gt;&lt;P&gt;- Diabled every security service in line&lt;/P&gt;&lt;P&gt;- Enabled TCP MSS with standard value (40 for ipv4)&lt;/P&gt;&lt;P&gt;- Enabled/ disabled NAT Traversal for Branch (because of the&amp;nbsp;NAT)&lt;/P&gt;&lt;P&gt;- Checked every single interface negoatiation, especially for WAN routers and Firewall&lt;/P&gt;&lt;P&gt;- Cryptosets down from very high, to very low (sha1, dh2, aes128)&lt;/P&gt;&lt;P&gt;- Different routing options for next hop when routed to the tunnel (next hop, non)&lt;/P&gt;&lt;P&gt;- Tunnelinterface automaticly adjusts mtu to 1428 (show vpn flow tunnel-id 1) on Branche site&lt;/P&gt;&lt;P&gt;- no drops, discards, erros on WAN and tunnel interface (show interface...)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Additional:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Very strange is, that the Branch connections to the HQ work, when im using same ISPs, but a Linogate Defendo Firewall for both sites... (the Linogate Defendo System is an old system which was in place bevor our migration)&lt;/P&gt;&lt;P&gt;... just to clarify.. the Linogate system reboots when i am altering a interface... so this is the worsed product i ve ever seen...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Today i started to migrate the second Branch --&amp;gt; same issue !&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Finally i am at the end of my knowledge...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please community, give me some input to this one&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Tony&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 14 Jun 2018 14:38:16 GMT</pubDate>
    <dc:creator>itserviceHEWA</dc:creator>
    <dc:date>2018-06-14T14:38:16Z</dc:date>
    <item>
      <title>Slow VPN performance in &gt;ONE&lt; direction</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/slow-vpn-performance-in-gt-one-lt-direction/m-p/217932#M63020</link>
      <description>&lt;P&gt;Hello Community,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i have a strange problem regarding VPN.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here is my setup:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;HQ:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- PA3020 vsys2 connects to a 100/100Mbit WAN. (local, stable provider)&lt;/P&gt;&lt;P&gt;- Public IP is configured directly on a interface of the PA&lt;/P&gt;&lt;P&gt;- Speedtest from local network in HQ commits the 100/100Mbit&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Branch:&lt;/P&gt;&lt;P&gt;- PA220 connects to a 50/10Mbit Vodafone WAN&lt;/P&gt;&lt;P&gt;- NAT will be applied on the WAN interface of the PA220, so i dont have to configure routing on the Vodafone box.&lt;/P&gt;&lt;P&gt;- NAT will be applied on the Vodafone box to communicate to the internet&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Because it is not a business line, i have to work with the transfernetwork between Vodafone box an PA220&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- Speedtest for local internetconnection wich passes the PA220 gives me 50/10Mbit - everything is fine.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Problem:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- When i am uploading from Branch to HQ, i get full 10MBIT&lt;/P&gt;&lt;P&gt;- When i am uploading from HQ to Branch, i get a maximum ov 2-5&amp;nbsp; MBIT out of the 50MBit&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What have i tested:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- Different MTU sizes for tunnel and WAN interfaces, from 1500 down to 1260&lt;/P&gt;&lt;P&gt;- Diabled every security service in line&lt;/P&gt;&lt;P&gt;- Enabled TCP MSS with standard value (40 for ipv4)&lt;/P&gt;&lt;P&gt;- Enabled/ disabled NAT Traversal for Branch (because of the&amp;nbsp;NAT)&lt;/P&gt;&lt;P&gt;- Checked every single interface negoatiation, especially for WAN routers and Firewall&lt;/P&gt;&lt;P&gt;- Cryptosets down from very high, to very low (sha1, dh2, aes128)&lt;/P&gt;&lt;P&gt;- Different routing options for next hop when routed to the tunnel (next hop, non)&lt;/P&gt;&lt;P&gt;- Tunnelinterface automaticly adjusts mtu to 1428 (show vpn flow tunnel-id 1) on Branche site&lt;/P&gt;&lt;P&gt;- no drops, discards, erros on WAN and tunnel interface (show interface...)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Additional:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Very strange is, that the Branch connections to the HQ work, when im using same ISPs, but a Linogate Defendo Firewall for both sites... (the Linogate Defendo System is an old system which was in place bevor our migration)&lt;/P&gt;&lt;P&gt;... just to clarify.. the Linogate system reboots when i am altering a interface... so this is the worsed product i ve ever seen...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Today i started to migrate the second Branch --&amp;gt; same issue !&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Finally i am at the end of my knowledge...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please community, give me some input to this one&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Tony&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 14 Jun 2018 14:38:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/slow-vpn-performance-in-gt-one-lt-direction/m-p/217932#M63020</guid>
      <dc:creator>itserviceHEWA</dc:creator>
      <dc:date>2018-06-14T14:38:16Z</dc:date>
    </item>
    <item>
      <title>Re: Slow VPN performance in &gt;ONE&lt; direction</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/slow-vpn-performance-in-gt-one-lt-direction/m-p/218032#M63037</link>
      <description>&lt;P&gt;Hello Community,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;working the whole week on this problem, i finaly resolved it.&lt;/P&gt;&lt;P&gt;Unfortunatelly it was a failure in my troubleshooting process, because the answer is one of my tested tasks.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For some reason i failed in testing the tunnel MTU sizes, because i didnt kill/ reconnect the tunnel in a clean manner.&lt;/P&gt;&lt;P&gt;(&amp;nbsp;"clear vpn ike-sa gateway &amp;lt;gateway&amp;gt;" and&amp;nbsp;&amp;nbsp;"test vpn ike-sa gateway &amp;lt;gateway&amp;gt;") after i configured the tunne MTUs...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;After configuring the tunnel MTU with a value of 1400 on both sites and than clear + test vpn via CLI, the problem was resolved. Now i get about 95% of the WAN speeds over the tunnel in both directions!!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The problem is the Vodafone Router in between the tunnel. (Branch Offices)&lt;/P&gt;&lt;P&gt;The PAs correctly handle the overhead, which is shown by the following command: "&lt;SPAN&gt;show vpn flow tunnel-id 1".&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;But the PAs cant recognize the headers, which are done by the Vodafone Router, because it is in line of the tunnel.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;So - as pointed out in a lot of documents on the network, the administrator has to calculate the overhead from that box.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;After this was done, everything is working as intended.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Best regards,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Tony&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;P.s.: This thread can be closed &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 15 Jun 2018 09:45:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/slow-vpn-performance-in-gt-one-lt-direction/m-p/218032#M63037</guid>
      <dc:creator>itserviceHEWA</dc:creator>
      <dc:date>2018-06-15T09:45:09Z</dc:date>
    </item>
    <item>
      <title>Re: Slow VPN performance in &gt;ONE&lt; direction</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/slow-vpn-performance-in-gt-one-lt-direction/m-p/539489#M110671</link>
      <description>&lt;P&gt;Hi dear,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;would you be so kind to help me troubleshooting the same issue? Download speed is&amp;nbsp;terribly slow, and I´m not talking about Internet, just inside the LAN. Tried to set a lower MTU both side but didn´t help...&lt;BR /&gt;By the way, is it right that if the issue is actually about the MTU we are going to see lots of fragmented packets on the PA side?&lt;BR /&gt;Thanks a lot ahead, Gian.&lt;/P&gt;</description>
      <pubDate>Thu, 20 Apr 2023 07:03:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/slow-vpn-performance-in-gt-one-lt-direction/m-p/539489#M110671</guid>
      <dc:creator>gianmaxfactor</dc:creator>
      <dc:date>2023-04-20T07:03:59Z</dc:date>
    </item>
  </channel>
</rss>

