<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VPN client slows upload to 1%! in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-client-slows-upload-to-1/m-p/109046#M9241</link>
    <description>&lt;P&gt;Yes, using the endpoint client only as remote access.&amp;nbsp; I just found that we are investigating if Zscaler's client is causing latency in another case, so that may be the issue.&amp;nbsp; We just recently deployed it.&lt;/P&gt;</description>
    <pubDate>Wed, 27 Jan 2021 14:22:55 GMT</pubDate>
    <dc:creator>George_Ellis</dc:creator>
    <dc:date>2021-01-27T14:22:55Z</dc:date>
    <item>
      <title>VPN client slows upload to 1%!</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-client-slows-upload-to-1/m-p/108993#M9239</link>
      <description>&lt;P&gt;Hi folks,&lt;/P&gt;&lt;P&gt;I have an open case on SmartConsole dropping my connections.&amp;nbsp; While investigating, I found something rather disturbing.&amp;nbsp; We split tunnel.&amp;nbsp; I am on AT&amp;amp;T "1gb" internet fiber.&amp;nbsp; Normally, my upload in speed tests runs about 150+mbps.&amp;nbsp; When I connect the IPSec VPN client, my upload rate drops below 1mbps on the internet side and inside the tunnel (verified by another member in our group).&amp;nbsp; The virtual adapter says it is at 1gbps.&amp;nbsp; I have tried this on both wired and wireless (diff adapter stacks, but same family, Realtek.)&amp;nbsp; Download speed remains above 300mbps.&lt;BR /&gt;&lt;BR /&gt;Has anyone solved for this in the past?&lt;/P&gt;</description>
      <pubDate>Wed, 27 Jan 2021 12:10:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-client-slows-upload-to-1/m-p/108993#M9239</guid>
      <dc:creator>George_Ellis</dc:creator>
      <dc:date>2021-01-27T12:10:07Z</dc:date>
    </item>
    <item>
      <title>Re: VPN client slows upload to 1%!</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-client-slows-upload-to-1/m-p/109044#M9240</link>
      <description>&lt;P&gt;Are you using Endpoint client for remote access only?&lt;/P&gt;
&lt;P&gt;Are there any other client-side security solutions installed that may be trying to proxy your traffic via IPSec?&lt;/P&gt;</description>
      <pubDate>Wed, 27 Jan 2021 14:06:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-client-slows-upload-to-1/m-p/109044#M9240</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2021-01-27T14:06:54Z</dc:date>
    </item>
    <item>
      <title>Re: VPN client slows upload to 1%!</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-client-slows-upload-to-1/m-p/109046#M9241</link>
      <description>&lt;P&gt;Yes, using the endpoint client only as remote access.&amp;nbsp; I just found that we are investigating if Zscaler's client is causing latency in another case, so that may be the issue.&amp;nbsp; We just recently deployed it.&lt;/P&gt;</description>
      <pubDate>Wed, 27 Jan 2021 14:22:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-client-slows-upload-to-1/m-p/109046#M9241</guid>
      <dc:creator>George_Ellis</dc:creator>
      <dc:date>2021-01-27T14:22:55Z</dc:date>
    </item>
    <item>
      <title>Re: VPN client slows upload to 1%!</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-client-slows-upload-to-1/m-p/109048#M9242</link>
      <description>&lt;P&gt;Can you temporarily uninstal the Zscaler from your endpoint and test upload speeds from it via both legs of split tunnel?&lt;/P&gt;</description>
      <pubDate>Wed, 27 Jan 2021 14:29:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-client-slows-upload-to-1/m-p/109048#M9242</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2021-01-27T14:29:47Z</dc:date>
    </item>
    <item>
      <title>Re: VPN client slows upload to 1%!</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-client-slows-upload-to-1/m-p/109054#M9243</link>
      <description>&lt;P&gt;Once, but then I won't work there anymore.&amp;nbsp; &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&amp;nbsp; It is inside our team, so we are working it now.&amp;nbsp; Just discovered after I posted when the Zscaler lead said they were working a problem.&amp;nbsp; Light bulb.&amp;nbsp; Extra proxy layer.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 27 Jan 2021 15:03:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-client-slows-upload-to-1/m-p/109054#M9243</guid>
      <dc:creator>George_Ellis</dc:creator>
      <dc:date>2021-01-27T15:03:32Z</dc:date>
    </item>
    <item>
      <title>Re: VPN client slows upload to 1%!</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-client-slows-upload-to-1/m-p/109055#M9244</link>
      <description>&lt;P&gt;Let me guess, if you use HTTPS/TLS as the VPN transport instead of IPSec, performance is just great.&lt;/P&gt;
&lt;P&gt;You have a low MTU in your network path somewhere, or somehow the VPN client is affecting the MTU when it is active.&amp;nbsp; The symptom of this is terrible performance due to packet loss because of the inability to fragment IPSec traffic due to the DF bit being set.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;To verify, run &lt;STRONG&gt;netstat -sv&lt;/STRONG&gt;&amp;nbsp;in Windows and note the counters associated with IP frags and TCP segment retransmissions.&amp;nbsp; Initialize the VPN tunnel with IPSec and start a big TCP-based upload.&amp;nbsp; Which frag/retransmit counters in the &lt;STRONG&gt;netstat -sv&lt;/STRONG&gt; output jump?&amp;nbsp; This should give you some idea of where to look.&lt;/P&gt;</description>
      <pubDate>Wed, 27 Jan 2021 15:04:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-client-slows-upload-to-1/m-p/109055#M9244</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2021-01-27T15:04:15Z</dc:date>
    </item>
  </channel>
</rss>

