08-29-2017 02:43 AM
Hello,
Clients who are connected via GlobalProtect VPN are experiencing slowness with all their traffic traversing the VPN (ie.. Internet and Server access traffic).
The latency is between 200-400ms for all the traffic regardless of whether its Internet based (to google) or server based (to our corporate servers).
Can you suggest any troubleshooting steps for this? Any relevant article to check?
Thanks in advance.
09-01-2017 07:36 AM
In GlobalProtect client, Details tab.
Check if protocol is SSL or IPSec.
If it is SSL then check if you permit udp 4501 towards GlobalProtect gateway.
Also check that you have "Enable IPSec" checked in GlobalProtect gateway config (Tunnel Settings tab).
09-01-2017 07:36 AM
In GlobalProtect client, Details tab.
Check if protocol is SSL or IPSec.
If it is SSL then check if you permit udp 4501 towards GlobalProtect gateway.
Also check that you have "Enable IPSec" checked in GlobalProtect gateway config (Tunnel Settings tab).
09-01-2017 07:54 AM
So you mean to permit udp 4501 in to the firewall using a security policy permiting it? I have a rule coming in to the firewall for the global protect client that has service any and I still get complaints from users that it still too slow.
I looked in network/interfaces/tunnel and I don't see a place in enable ipsec but I do see it enabled when I go to the globalprotect gateway configuration
09-01-2017 07:59 AM - edited 09-01-2017 08:00 AM
If you run GlobalProtect on your untrust interface and you don't have block any-any rule added then last interzone-default will permit from untrust to untrust 4501.
If you run GlobalProtect gateway on loopback and then you need to NAT udp 4501 to this loopback.
GlobalProtect agent will try IPSec 3 times and then falls back to SSL.
In case SSL it is TCP inside TCP (tcp meltdown and other issues can occure).
Enable IPSec is in firewall.
09-01-2017 08:05 AM
If agent view shows IPSec then issue is somewhere else.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!