- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hi folks,
I have an open case on SmartConsole dropping my connections. While investigating, I found something rather disturbing. We split tunnel. I am on AT&T "1gb" internet fiber. Normally, my upload in speed tests runs about 150+mbps. When I connect the IPSec VPN client, my upload rate drops below 1mbps on the internet side and inside the tunnel (verified by another member in our group). The virtual adapter says it is at 1gbps. I have tried this on both wired and wireless (diff adapter stacks, but same family, Realtek.) Download speed remains above 300mbps.
Has anyone solved for this in the past?
Are you using Endpoint client for remote access only?
Are there any other client-side security solutions installed that may be trying to proxy your traffic via IPSec?
Yes, using the endpoint client only as remote access. I just found that we are investigating if Zscaler's client is causing latency in another case, so that may be the issue. We just recently deployed it.
Can you temporarily uninstal the Zscaler from your endpoint and test upload speeds from it via both legs of split tunnel?
Once, but then I won't work there anymore. 🙂 It is inside our team, so we are working it now. Just discovered after I posted when the Zscaler lead said they were working a problem. Light bulb. Extra proxy layer.
Let me guess, if you use HTTPS/TLS as the VPN transport instead of IPSec, performance is just great.
You have a low MTU in your network path somewhere, or somehow the VPN client is affecting the MTU when it is active. The symptom of this is terrible performance due to packet loss because of the inability to fragment IPSec traffic due to the DF bit being set.
To verify, run netstat -sv in Windows and note the counters associated with IP frags and TCP segment retransmissions. Initialize the VPN tunnel with IPSec and start a big TCP-based upload. Which frag/retransmit counters in the netstat -sv output jump? This should give you some idea of where to look.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 4 | |
| 3 | |
| 2 | |
| 2 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY