Since we have upgraded Management and Gateways to R80.20 T101 we've had a lot of latency issues with SCCM imaging our laptops. A 13500 appliance sits between the imaging laptop and the SCCM server.
In our packet captures we can see 3 Retransmission packets before a 4th allows traffic through. This behavior happens continuously. We believe this is the cause for the laptops that took 45 mins to image to now take 3.5 hours.
The following Blades are active:
FW,VPN,IPS,App,URL,AV,AB
The FW policy allows connection to the imaging server using standard TCP and UDP ports. But the rest of the policy in other sections is using Updateable Objects (to support O365) and domain objects. I state that other information because I'm not sure if that will affect performance.
We have tried the follow actions to address the issue without success:
Rebuilt SCCM Management Point and Distro Points.
Failover to the standby cluster member
disable fwaccel
Ensured there were no drops in FW policy
created custom application risk level low
Unchecked "Block requests when web service is unavailable" in Blades - AppControl Advanced Settings
In Blades - AppControl - Website categorization mode: Background
In Blades - Threat Prevention- Website categorization mode: Background
Validated the networking is solid the whole way. The laptop images fine when the gateway isn't in the path.
CPU runs less than 10% average
All errors resolved in a zdebug + drop
I would appreciate some suggestions on where to look next.
_Vic_