IPSec Tunnel performance tips?

Reply
L4 Transporter

IPSec Tunnel performance tips?

Hello folks,

 

I've seen a this article about improving performance by enabling this Adjust TCP MSS.  Ours is not enabled.

https://live.paloaltonetworks.com/t5/Management-Articles/How-to-Improve-Performance-for-IPSec-Traffi...

 

Would this be enabled on the public internet facing interface?

I do see some TCP retransmission and reassembled messages in the pcap. 

 

Our IPSec peer is complaining the application they are using from our side is very slow running and downloading Oracle Apex reports.  Blaming the network and IPSec tunnel since the reports run much faster from Starbucks WiFi.

 

Wondering if anyone may have a suggestion or comment?

 

ipsec_performance.jpg

 

 

L7 Applicator

Re: IPSec Tunnel performance tips?

Hello,

While I could be wrog, I think the change should be made on the layer 3 interface you have your portal/gateway config connected to.

 

Regards,

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!