VPN Performance over Prisma Access : slow downloads

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

VPN Performance over Prisma Access : slow downloads

L3 Networker

Hi,

 

Can somebody tell met what you can expect from downloading a file over prisma access backbone.

Our datacenter is connected to service connection and when I try to download a 200 Mbps file from the datacenter to a remote network located in the same region, I am getting a download speed of 500Kbps per second.(smb transfer)

Within the remote site copying a large file over the firewall from a local file server I am getting speeds up to 35 Mbps and increasing, so threat inspection or local firewall doesn't seem to be the issue.

The remote site has a 200/200 link the DC has a 500/500 link.

 

 

7 REPLIES 7

L1 Bithead

We are having similar problems but unfortunately non of the PAN support team have been able to resolve the issue.

The only actions they did today was repeated packet captures and then they keep changing engineers to gain time.

This is negatively impacted business and it seems that PAN does not care.

The issue has been reported more than 3 months back and still pending!

Hi NuvinG,

 

Troubleshooting performance issues is always hard.   Are you experiencing slowness in all kinds of traffic or only SMB traffic?

SMB protocol is not the most performing protocol it was never designed to be used on higher latency networks.

You can try some things,

1. Make sure dns is not slowing you down.

2. Test if you IPSEC tunnel on global protect client works faster then over SSL.

3.  Disable inspections on SMB traffic.

4.  use ipert to test you speed.

 

L1 Bithead

Hi  zGomez,

Thank you for this and we have been working with PAN support and they are still struggling.

We have also been disabling SMB multichannel (Deploy SMB Multichannel | Microsoft Learn)

So up to now this is still an issue.

Thanks

 

Hello,

 

Did you try disabling all inspection for SMB? Or dit an app override for SMB. Is there any other application going slow? Or only SMB. What speeds are you getting? Can you do a test with iperf and post output.

can you maybe do a packet capture on client side and firewall.  What are the MTU settings on your tunnel interface?

are you using SSL or IPSEC for your global protect client. 

@NuvinG I see that you are using SC and RN. Are you using PANW NGFWs to Prisma Access? 

 

NGFW -- Prisma Access -- NGFW? What models?

 

Regards

 

--Richard

L1 Bithead

We're having the same issue. We have tried disabling SMB multichannel on client/server, app override, and DSRI, but there is no change. Now Palo is trying to get us to buy app accelerator which isn't cheap. We decided to test it out in our lab and file transfers are actually slower!! And now we're being asked to use a different application instead of SMB. This is ridiculous as much as we are paying. 

Palo did the same thing with us. They will probably try to sell you on app acceleration which is another feature that you will have to pay for.  They can't get that to work either!

  • 4151 Views
  • 7 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!