Help with network design

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Help with network design

L0 Member

So my network consists of a PA200, a Juniper SRX, 2 servers, a VOIP phone, and a WAP. 

 

I recently configured the PA-200 with 3 subinterfaces for the 172.16.2.1/24, 172.16.3.1/24, and 172.16.4.1/24 networks. The Juniper port was configured with as a trunk and allowed all these vlans across. The interfaces on the SRX were configured for the appropriate VLAN and all of them could hit their respective .1 IPs on the Palo. 

 

Here's my issue. Traffic was UNBEARABLY slow. Connectivity was there but web traffic was often not fast enough to actually connect to the webpage.

 

The Palo was configured as bare bones as possible. An Allow all policy, a single NAT for internet, one trunk interface to the switch and one internet facing link, one virtual route, and no features applied to the interface.

 

This is a very standard design, and one I've actually implemented at client sites, but I must be missing something here. 

 

I'm just looking for simple design pointers to get the switch and palo configured correctly.

2 REPLIES 2

Cyber Elite
Cyber Elite

Try lookig at the global counters to see if something odd surfaces (extreme amount of fragmentation maybe?)

 

> show counter global filter delta yes

next you could try setting the interface speed and duplex statically on all connected devices and switch

 

 

Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization

L2 Linker

Is the SRX doing any sort of filtering? Are you double natting? ie doing NAT on the juniper and the PAN? 

 

Sounds like you are using the SRX as a switch? Hopefully L2 only? clients/servers are using the PAN as their gateway?

 

The fact that its working at all indicates asymetric routing is not the issue (i.e client > juniper > PAN > Internet > PAN > client - so not returning to the client via the Juniper), but can you confirm the L3 flow is (client > PAN > Internet > PAN > client)?

 

 

Is performance slow for traffic other than web browsing?

 

A common issue I see with web browsing performance issues specifically is using DNS servers separate to the ISP-provided ones. Any changes in this space?

 

  • 1975 Views
  • 2 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!