Recommended MTU for GlobalProtect Gateway

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Recommended MTU for GlobalProtect Gateway

L4 Transporter

Hello,

 

We’re experiencing slowness from global connect clients located offsite back to firewall (i.e. 5MBps). Without the VPN client, the user can get up to 60MBps.

 

What is the recommended MTU settings for GlobalProtect Gateway/interface should be set at? Our Ethernet interface(1/3) MTU where gateway terminates in DMZ is set at 1350 and the tunnel.11 is set to 1400. Does this need to be the same?

I have already checked the KB below.

 

https://live.paloaltonetworks.com/t5/Management-Articles/How-to-Improve-Performance-for-IPSec-Traffi...

 

Thanks in advance.

5 REPLIES 5

Cyber Elite
Cyber Elite

Open GlobalProtect client.

Go to Details tab.

Is protocol SSL or IPSec?

If SSL then check if you are blocking incoming UDP port 4501 towards GlobalProtect Gateway.

SSL runs over TCP.

IPSec runs over UDP and avoids TCP meltdown issue.

Enterprise Architect, Security @ Cloud Carib Ltd
Palo Alto Networks certified from 2011

Hi,

 

Checked all that you mentioned is fine. Clients connecting using IPSEC.

How do you measure speed?
Do you have public website in your environment you could place some big file and try to download it without GP over public internet and with GP connected over tunnel?

Enterprise Architect, Security @ Cloud Carib Ltd
Palo Alto Networks certified from 2011

Hi Raido,

 

Yes, we have a FTP service in the DMZ on same interface and speed is fine.

 

All we really want to know is what should the MTU settings on the tunnel vs interface be set at?

 

We have tried setting interface to 1360, tunnel MTU to 1400 and select Adjust TCP MSS.

 

Getting 10MB down/10MB up. Without VPN we’re getting 40MB down/27MB up.

 

Is this what we should be seeing for GP VPN?

You have 0.0.0.0/0 route so all traffic goes into tunnel when GP is connected?

I have not changed MTU in my environment so using default.

Currently at home with 20Mbit down and I get same result (+/- 1Mbit) with and without GlobalProtect (no split tunneling, using 0.0.0.0/0 route in my GP config).

 

Test with http://www.speedtest.net

What is speed and latency when GP is on and when GP is off?

 

Any QoS in use?

Enterprise Architect, Security @ Cloud Carib Ltd
Palo Alto Networks certified from 2011
  • 7571 Views
  • 5 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!