02-27-2020 10:32 AM
I have created S2S Tunnel (IKEv2) between a CIsco ASA and a Palo Alto at the remote site... users are reporting slowness while accessing sites hosted at Data Center through the tunnel. Bandwidth and utilization at both locations is fine and that does not seem to be the issue. Can someone please suggest what could be the issue here.
Thanks
02-27-2020 10:43 AM
02-27-2020 11:08 AM
was this tunnel slow from day 1 or just recently it get slow? any changes made in your network or remote side?
which firewall is initiator and which firewall is responder? if you run a ping from one remote site to other what is the response time you get?
02-27-2020 11:45 AM
Hi,
If everything looks normal on both devices (load, link capacity), look at possibly MTU and pathMTU causing slowness. Check this document out and make necessary changes the ASA side, Palo Alto does the necessary changes to MSS/MTU by itself:
Check fragment drops on the ASA with "show fragments".
Regards,
Cristian Matei.
02-28-2020 12:39 AM
@Cristian Matei how are you? change the fragment path need on ikev2 or on the interface of the ASA? if changing the ASA MTU on the firewall it will not impact the other traffic which is going outbound toward internet?
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide