What is your experience of using site-to-site VPN with PA devices and how is the performance?

Showing results for 
Show  only  | Search instead for 
Did you mean: 

What is your experience of using site-to-site VPN with PA devices and how is the performance?

L6 Presenter

Im looking for those with reallife experience from running site-to-site VPN with PA devices both pro (good) and con (bad) stuff that might float up to the surface.


How is the reliability, how is the performance, how is the troubleshooting (if any) etc?


For example looking at this test http://blog.webernetz.net/2016/07/26/palo-alto-vpn-speedtests/ using PA-200 it shows an average of (give or take) 198-271Mbps (depending on cipher being used) with IPsec while the datasheet for PA-200 says 50Mbps IPsec.


Can you assume the same (4-5x compared to the datasheet numbers) for lets say the PA-3000 and PA-5000 (and while we are at it the PA-7000 too) series who in the datasheet says 500Mbps (PA-3000) for IPsec (that is this would actually mean it (PA-3000) would be able to handle 2-2.5Gbps of IPsec in other terms "wirespeed" on a 1Gbps full duplex uplink)?


Does perhaps PA themselfs have some numbers that can be provided in this community forum or for that matter any of the forum members who might have somewhat fresh numbers mainly on the performance figures and which ciphers and PA-model you were using?


Also are there any performance recommendations (when it comes to IPsec and PA) other than the obvious one to enable "Adjust TCP MSS" as described in https://live.paloaltonetworks.com/t5/Management-Articles/IPSec-and-tunneling-resource-list/ta-p/6772... ?


Cyber Elite
Cyber Elite


I have been running site-to-site VPN's with PAN's to PAN's and PAN's to ASA's, etc for years. So far everything works. I have not seen a performance issue that was a show stopper. Ususally the reliability of hte ISP was more in question than the VPN endpoints.


Hope this helps.



What about the performance for IPsec vs what PA themself states in the datasheets for each model?


As seen for PA-200 the actual throughput is 4-5x the numbers specified in the datasheet but what about the other models (since PA-200 is a bit odd which uses one x86 for its dataplane and no hardware offloading)?

I have to admit I didnt perform speed tests, however poor performance was usually due to low bandwidth sites or the ISP having issues.

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!