<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: GlobalProtect clients experiencing latency delays in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-clients-experiencing-latency-delays/m-p/386734#M90294</link>
    <description>&lt;P&gt;Hi there! I know this thread is older...but how do you create a DNAT for 4501 AND 443?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For example, I have gateway configured with x.x.x.x:7000&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a DNAT that forwards 7000 to 443.&amp;nbsp; How do I get it working with 4501? reason I ask is because I want my tunnel to use IPSEC rather than SSL.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you!!&lt;/P&gt;</description>
    <pubDate>Fri, 19 Feb 2021 03:17:32 GMT</pubDate>
    <dc:creator>dejesusv</dc:creator>
    <dc:date>2021-02-19T03:17:32Z</dc:date>
    <item>
      <title>GlobalProtect clients experiencing latency delays</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-clients-experiencing-latency-delays/m-p/173577#M54615</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Clients who are connected via GlobalProtect VPN are experiencing slowness with all their traffic traversing the VPN (ie.. Internet and Server access traffic).&lt;/P&gt;&lt;P&gt;The latency is between 200-400ms for all the traffic regardless of whether its Internet based (to google) or server based (to our corporate servers).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you suggest any troubleshooting steps for this? Any relevant article to check?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Aug 2017 09:43:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-clients-experiencing-latency-delays/m-p/173577#M54615</guid>
      <dc:creator>Farzana</dc:creator>
      <dc:date>2017-08-29T09:43:42Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect clients experiencing latency delays</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-clients-experiencing-latency-delays/m-p/174351#M54793</link>
      <description>&lt;P&gt;In GlobalProtect client, Details tab.&lt;/P&gt;&lt;P&gt;Check if protocol is SSL or IPSec.&lt;/P&gt;&lt;P&gt;If it is SSL then check if you permit udp 4501 towards GlobalProtect gateway.&lt;/P&gt;&lt;P&gt;Also check that you have "&lt;SPAN&gt;Enable IPSec" checked in GlobalProtect gateway config (Tunnel Settings tab).&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 01 Sep 2017 14:36:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-clients-experiencing-latency-delays/m-p/174351#M54793</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2017-09-01T14:36:16Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect clients experiencing latency delays</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-clients-experiencing-latency-delays/m-p/174356#M54796</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/15603"&gt;@Raido_Rattameister&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So you mean to permit udp 4501 in to the firewall using a security policy permiting it? &amp;nbsp;I have a rule coming in to the firewall for the global protect client &amp;nbsp;that has service any and I still get complaints from users that it still too slow.&lt;/P&gt;&lt;P&gt;I looked in network/interfaces/tunnel and I don't see a place in enable ipsec but I do see it enabled when I go to the globalprotect gateway configuration&lt;/P&gt;</description>
      <pubDate>Fri, 01 Sep 2017 14:54:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-clients-experiencing-latency-delays/m-p/174356#M54796</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2017-09-01T14:54:07Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect clients experiencing latency delays</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-clients-experiencing-latency-delays/m-p/174358#M54797</link>
      <description>&lt;P&gt;If you run GlobalProtect on your untrust interface and you don't have block any-any rule added then last interzone-default will permit from untrust to untrust 4501.&lt;/P&gt;&lt;P&gt;If you run GlobalProtect gateway on loopback and then you need to NAT udp 4501 to this loopback.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;GlobalProtect agent will try IPSec 3 times and then falls back to SSL.&lt;/P&gt;&lt;P&gt;In case SSL it is TCP inside TCP (tcp meltdown and other issues can occure).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Enable IPSec is in firewall.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Enable IPSec.PNG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/10987iB1DC6B2E689A2B19/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Enable IPSec.PNG" alt="Enable IPSec.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 01 Sep 2017 15:00:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-clients-experiencing-latency-delays/m-p/174358#M54797</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2017-09-01T15:00:32Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect clients experiencing latency delays</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-clients-experiencing-latency-delays/m-p/174361#M54799</link>
      <description>&lt;P&gt;If agent view shows IPSec then issue is somewhere else.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="IPSec.PNG" style="width: 383px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/10988iDCF0338A5BC17C53/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="IPSec.PNG" alt="IPSec.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 01 Sep 2017 15:05:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-clients-experiencing-latency-delays/m-p/174361#M54799</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2017-09-01T15:05:46Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect clients experiencing latency delays</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-clients-experiencing-latency-delays/m-p/174362#M54800</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/15603"&gt;@Raido_Rattameister&lt;/a&gt;&lt;/P&gt;&lt;P&gt;Yes I have IPSEC enabled in the location in your screenshot. &amp;nbsp;I am using the SSL protocol to connect. &amp;nbsp;I must add I did not do the original configuration of the VPN's I have got them to work and now I am working at getting them to work as efficiently as I can.&lt;/P&gt;&lt;P&gt;I didn't find any NATTING concerning the loopbacks used for the VPN's&lt;/P&gt;</description>
      <pubDate>Fri, 01 Sep 2017 15:13:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-clients-experiencing-latency-delays/m-p/174362#M54800</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2017-09-01T15:13:19Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect clients experiencing latency delays</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-clients-experiencing-latency-delays/m-p/174363#M54801</link>
      <description>&lt;P&gt;If GP agent shows SSL as protocol it can't connect with IPSec.&lt;/P&gt;&lt;P&gt;Go to Monitor &amp;gt; Traffic and use filter below.&lt;/P&gt;&lt;P&gt;( port.dst eq 4501 )&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Do you see it being blocked?&lt;/P&gt;</description>
      <pubDate>Fri, 01 Sep 2017 15:15:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-clients-experiencing-latency-delays/m-p/174363#M54801</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2017-09-01T15:15:25Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect clients experiencing latency delays</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-clients-experiencing-latency-delays/m-p/174372#M54803</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/15603"&gt;@Raido_Rattameister&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Port 4501 is not being blocked for legitimate traffic to the loopback for the VPN&lt;/P&gt;</description>
      <pubDate>Fri, 01 Sep 2017 15:22:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-clients-experiencing-latency-delays/m-p/174372#M54803</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2017-09-01T15:22:52Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect clients experiencing latency delays</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-clients-experiencing-latency-delays/m-p/174396#M54806</link>
      <description>&lt;P&gt;Earlier you mentioned you saw no natting but now you mention that GP runs on loopback.&lt;/P&gt;&lt;P&gt;If it runs on loopback there must be DNAT in place.&lt;/P&gt;</description>
      <pubDate>Fri, 01 Sep 2017 16:17:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-clients-experiencing-latency-delays/m-p/174396#M54806</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2017-09-01T16:17:46Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect clients experiencing latency delays</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-clients-experiencing-latency-delays/m-p/174434#M54814</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/15603"&gt;@Raido_Rattameister&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Good point I will check again on the natting&lt;/P&gt;</description>
      <pubDate>Fri, 01 Sep 2017 20:55:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-clients-experiencing-latency-delays/m-p/174434#M54814</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2017-09-01T20:55:19Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect clients experiencing latency delays</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-clients-experiencing-latency-delays/m-p/174445#M54818</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/15603"&gt;@Raido_Rattameister&lt;/a&gt;&lt;/P&gt;&lt;P&gt;I also run different portals/gateways on loopbackinterfaces ... but I do not NAT at all in this case. All the loopbacks simply have public IPs so there is no need for DNAT&lt;/P&gt;</description>
      <pubDate>Fri, 01 Sep 2017 22:32:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-clients-experiencing-latency-delays/m-p/174445#M54818</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2017-09-01T22:32:30Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect clients experiencing latency delays</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-clients-experiencing-latency-delays/m-p/174456#M54821</link>
      <description>&lt;P&gt;True it can use external IP but if agent connects overr SSL then most likely it is either Security Policy or NAT that is not configured correctly.&lt;/P&gt;&lt;P&gt;In some rare cases source network but quite rare nowadays.&lt;/P&gt;</description>
      <pubDate>Sat, 02 Sep 2017 00:06:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-clients-experiencing-latency-delays/m-p/174456#M54821</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2017-09-02T00:06:57Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect clients experiencing latency delays</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-clients-experiencing-latency-delays/m-p/386734#M90294</link>
      <description>&lt;P&gt;Hi there! I know this thread is older...but how do you create a DNAT for 4501 AND 443?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For example, I have gateway configured with x.x.x.x:7000&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a DNAT that forwards 7000 to 443.&amp;nbsp; How do I get it working with 4501? reason I ask is because I want my tunnel to use IPSEC rather than SSL.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you!!&lt;/P&gt;</description>
      <pubDate>Fri, 19 Feb 2021 03:17:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-clients-experiencing-latency-delays/m-p/386734#M90294</guid>
      <dc:creator>dejesusv</dc:creator>
      <dc:date>2021-02-19T03:17:32Z</dc:date>
    </item>
  </channel>
</rss>

