All things Palo Alto Networks

  • Blog

  • Forum

  • Members

  • More

    Use tab to navigate through the menu items.
    To see this working, head to your live site.
    • Categories
    • All Posts
    • My Posts
    onerobertone
    Mar 26, 2021

    IPSec Tunnel

    in General discussion

    Hello -

    Is there a good way to show speeds through the tunnel, usage, bandwidth and so on? The speed we are getting is what I'm most interested in.

    4 comments
    0
    Reaper
    Mar 26, 2021

    The best way is actually using SNMP and collecting statistics for the tunnel interface.

    A secondary approach is to enable QoS on the interface without setting a restrictive profile no limits, no QoS policy) you can then look at the live statistics for the encrypted traffic. drawback here is that you'll only get live statistics, nothing historical.


    myky
    Mar 26, 2021

    IPSec itself adds overhead, so you can put less "useful" data inside each packet, but there some things you could try:

    * sha-1

    * aes128

    Fast and secure hashing and encryption algorithms.


    Thanks,

    myky

    0
    Reaper
    Mar 26, 2021

    on this topic: use GCM instead of CBC, and diffie hellman groups 19 (256bit) or 20 (384bit) elliptic curve instead of large bit modulus (group 14 is 2048 bit modulus for example)

    onerobertone
    Mar 26, 2021

    Thank you both!

    4 comments
     
    • Mastering Palo Alto Networks
    • PANgurus LinkedIn

    Subscribe Form

    Privacy Policy

    Terms of use

    ©2020 by PANgurus.