Troubleshooting slow response to email via vpn

I've just adopted a vpn 3000 concentrator, and am totally learing this, so my apologies.
What could be reasons within a VPN enviroment that people are having slow response to email. (excluding issues with servers)
From a network perspective I can trouble shoot slow response, but how would a vpn enviroment be any more different to troubleshoot.
Naturally VPN is going to be much much slower, but taking 10 minutes for multiple users to get their email seems odd. LAN users get there email within seconds

Hi:
I'll tell you, I used to have the exact same problem at my last company.
We had an Exchange server for email and everyone used Cisco's VPN client.
Email was so slow, it was ridiculous sometimes. Everything else was OK, though. Other applications were OK, and network management was also good. It was just Exchange.
I know that Exchange is notorious for being delay intolerant, but this was bad! and it seemed to get worse with time.
Anyway, I dont know if you have done any troubleshooting yet or not, but you would definitely want to focus on the MTU settings for the VPN connection. Remember that IPSec adds overhead that may cause the ethernet frame to exceed the network's allowable MTU, so the packets get fragmented and reassembled at the receiving end. This can be a very slow process. And some applications are not very tolerant of fragmentation, like SQL and, I think, Exchange, too.
The problem with client VPN is that you would have to adjust each user's PC MTU. With site-to-site VPN, you can, of course, set the maximum segment size of the entire tunnel, so all users sitting behind the tunnel will be forced to conform to the tunnel's stips.
But you can try doing that on a few PCs to see if anything changes. I changed the PCs MTU using freeware called DR. TCP/IP. You can download it for free and it will allow you to change the PCs MTU very easily -- just a few keystrokes, instead of having to go into the registry and get stupid with Windows.
Change the output segment size for the PC to, say, 1400, and see if that improves anything. You would also want to change it on the 3000. I forgot how to do it on the 3000.
Victor

Similar Messages

  • Random users getting very slow response when opening messages/attachments or sending email

    I have a small number of users, mostly very senior management of course, who are experiencing slow response when trying to open email messages and attachments or send messages.
    They see the spinning wheel and sit there until it decides to open or send. If the message is opened  and closed again you would expect it to be quick reopening the same message, no, it does the same thing again.
    These users are all using Outlook 2010 and their mail accounts are on Exchange 2013. It does not seem to make a difference if they use a physical machine or log into a VDI.
    I do not have the same issue generally, though I have experienced this when using VDI and this has been seen using a number of different machine pools so it is not a specific pool.
    This is not specifically a VDI issue, as the 3rd paragraph says, the issues are seen on both physical and virtual machines.
    none of the mailboxes are particularly large, most are at around 60% of quota limit, and the same limit applies to almost all mailboxes across the organization. They also do not appear to have a huge number of messages stored, other users without issues
    have larger mailboxes and higher item counts. Any ideas what I need to look at to address this?

    Hi,
    How about OWA?
    If OWA works well, it seems an issue on the Outlook client side.
    Please try to run Outlook under safe mode and re-create profile for testing.
    Any related error/warning/information message left in App Log?
    Also consider the network Bandwidth.
    Thanks
    If you have feedback for TechNet Subscriber Support, contact
    [email protected]
    Mavis Huang
    TechNet Community Support

  • SLow response of WEb Servers via CSM

    Hi,
    I'm experiencing a slow response from my web servers via the CSM. After doing a sniffer trace it's show that the Vserver address does not reponse to the intial sync packet of the client but will only reponse to the second sync packets from the client. Thus the slowness of the reponse time.
    May I know why is this so ?
    Secondly I also notice the connection failure counter keeps going up for the "real servers" and the "CSM". May I know how does the CSM response to the client for a connection request. Does the CSM resonse immediately to the CLient via the VIP or does the CSM contact the REAL SERVERS first and once the REAL SERVERS resonded only then will it reponse back to the client.
    Thanks

    the CSM will loadbalance the SYN [unless you have a Layer 7 vserver - you can see the level with sho mod csm x vserver detail].
    Moreover, a connection failure indicates a server did not respond to a SYN or responded with a RESET.
    So, I would sugges to verify the level of your vserver [most probably not l7] and then check your servers.
    Make sure they sent traffic back to the CSM and not directly to the client.
    Make sure the server is alive.
    Regards,
    Gilles.

  • Very slow response, stopping for seconds in the middle of typing an email

    I'm having very slow response time with Firefox, so much so that I've switched to IE (gasp!). It'll stop suddenly for several seconds in the middle of typing an email and I have to wait to start typing again. Websites are timing out or just taking a very long time to respond after clicking on something. Yahoo in particular is extremely slow.

    For me, I think the "Skype Click to Call 5.11.0.9874" addon was causing the slow response. Once I disabled this addon Firefox was responding normally.

  • Email connectivity via VPN

    Hi,
    I'm currently unable to force a recieve email option via vpn on my nokia E72 phone. Details as follows:
    email setup: pop3/imap
    incoming: imap
    outgoing: smtp
    Nokia updates recent: yes.
    There is no "send/receive" option on the client and the "synchronise all" option appears to do nothing. I can create and send emails no problem, they are received by the addressee with no problems, I just can not receive emails or download/synchronise with my company email account.
    To connect I open the email client, choose the vpn connection, enter my username and appropriate passcodes, the connectivity is established, then no email is received, even if I syncrhonise.
    Any advice/help would be appreciated.

    Its a server which can be virtualized. You will  have to order it. 
    http://www.cisco.com/c/en/us/products/collateral/unified-communications/expressway-series/datasheet-c78-730478.html
    The top level part number is R-UCL-UCM-LIC-K9. You will need CUCM 9.1.2 or higher with CUPS to get it working. 

  • Ssh via vpn: typing commands hangs (is slow)

    Hello all,
    for a long time i have got an annoying problem and i would like to fix it in the near future.
    Establishing an ssh-connection via vpn from my Maxbook tomy FreeBSDsystem works
    without any problems: the the password-prompt immediately.
    But typing in any commands is very slow, it seems to hang anyhow. Typing with a normal
    speed is impossible because all letters after the first letters are missing. After 1-2 seconds
    the appear and i could keep on typing.
    Erasing is the same: i hit the key and it takes a while until the letters are disappearing.
    It remembers me a little bit at the keyboard-settings of MacOS itself: there you can configure
    the speed and so on.
    Has anybody an idea how to fix this?
    Here some general annotations:
    1) it is MacOS independent (10.5. and 10.6)
    2) is is FreeBSD idenpedent (8.0 and 8.2)
    3) it is terminal-application independent (MacOS-terminal and 3rdparty terminal).
    Thank you very much, Stefan

    Hi Darren,
    The user's vim session dies when the users are actively typing.
    As for there being a firewall or NAT device between the workstation and the server, yes, there is. The users are in one building and the server is housed in a datacenter in a separate building. The users do not have this issue with out other Solaris 8 and Solaris 10 servers...only this one particular server. A traceroute to the server takes only 5 hops and returns quickly.
    As for the logs, I just checked /var/adm/messages and it is reporting the following types of messages over and over.:
    [ID 317013 daemon.notice] bpcd[11746] from some IP
    I think these messages are generated from Veritas Netbackup which is administered by a separate team than what I am on, but I can have them investigate.

  • Access AFP, email, Remote Desktop via VPN and local network but NOT web

    How can I do this? Right now I can set up all these services where I can access them via VPN only, but not on the local network or via the web. If I want to access them via the local network I have to open up the ports in the firewall, however this opens up access via the web (not requiring VPN) which I do NOT want. How do I remedy this?

    How can I do this? Right now I can set up all these services where I can access them via VPN only, but not on the local network or via the web. If I want to access them via the local network I have to open up the ports in the firewall, however this opens up access via the web (not requiring VPN) which I do NOT want. How do I remedy this?

  • Slow finder Browsing when accessing LAN via VPN connexion

    I am running ML Server, latest upadte on a 2010 Mac Mini Server machine.
    When I am connected to my network from a remote location via VPN, and I try to browse my LAN structure with Finder, it takes ages for the list of folders/files to appear and refresh.
    I have checked my VPN configuration and tried different type (L2TP, PPTP) but nothing significantly differ in term of browsing speed.
    I also appreciate that the network connection at the remote location, as well as the upload speed on my local network can influence the overwal browsing speed... but after several test, I confirm I have more than 3 Mbps bandwith for upload on the local network, and 20 Mbps minimum on the remote location.
    I also tried AFP / SMB, but does not seem to change anything.
    So, I guess I hope the Community has already experienced the issue and some of you guys may have found a workaround to this issue.
    Many thanks.

    why not try cisco ipsec
    Input the following settings:
    Interface: VPN
    VPN Type: Cisco IPSec
    Service Name: This can be anything, I left the default.
    Edit the new interface details as follows:
    Server Address: cisco.vpntraffic.com or other country vpn such as Portugal VPN
    Account Name: Your vpn account
    Password: Your vpn password
    How to setup Mac OS X Built-In Cisco VPN

  • Access to DFS root via VPN not working - error 0x80070035 keeps popping up

    Dear all,
    when trying to access the DFS root via VPN from a Windows 7 non-domain member computer I always receive an error stating "Windows cannot access \\eggs.local\dfs", Error Code: 0x80070035, The Network Path was not found.
    I searched the internet as well as these forums in order to get to grips with this error message but didn't find anything to solve my problem.
    I made sure, that NetBIOS over TCP/IP is enabled, that I have access to the VPN adapter's DNS as well as WINS servers, that DNS name resolution is working properly, DNS split tunneling is enabled, Windows Firewall is disabled, and so forth. Still no luck.
    Any ideas?
    Thanks Alex
    Alexander Ollischer Diplom-Wirtschaftsinformatiker (FH) Citrix & Microsoft Certified Engineer (CCEA, CCEE, MCSA, MCSE, MCDBA, MCTS) Afontis IT+Services GmbH Baierbrunner Straße 15 81379 München Deutschland Telefon (089) 74 34 55-0 Fax (089) 74 34 55-55
    mailto:[email protected] http://www.afontis.de http://www.itganzeinfach.de Amtsgericht München, HRB 109 005 Geschäftsführer: Thomas Klimmer

    Hi,
    Though you mentioned DNS is working properly, please check if DNS forwarder is set as set correctly. 
    And incase it is caused by authentication, please try to force Kerberos to use TCP - by default it using UDP and on a slow VPN connection, UDP packets may be dropped. 
    How to force Kerberos to use TCP instead of UDP in Windows
    http://support.microsoft.com/kb/244474
    Also check NTFS and Sharing permission on top of the DFS Namespace. At least give users a Read permission. 
    If you have any feedback on our support, please send to [email protected]

  • Incredibly slow Browsing in finder over VPN

    I VPN into my work server - I'll be honest I don't know what server setup they are using other than it is Windows based - regardless, I get wonderful speeds browsing on an XP box but dismal if not Finder Killing speeds on my Mac just trying to get a directory listing - forget about transferring files. Often I have to relaunch the finder just to get back into browsing local files. The odd thing is that going through to the network share via terminal seems to be about 300x times faster.
    Browsing Internet through VPN seems normal enough, I can share music easily enough and email seems fairly robust, but any SMB share is slower than molasses. I have searched and searched for almost 2 hours now and tried pretty much every solution I found - nothing has worked. Duplex settings, ipV6 settings, hacking the smb config files etc. Nothing. Is anyone else running into this issue? I use the latest CISCO VPN client BTW - given to me by my admins at work.
    I know I have been less than informative on the server configs - I will grab what I can from my network admins tomorrow to see if that sparks any more ideas as to the issue. Any help is appreciated - I may just go nuts
    Message was edited by: ChrisLacey

    For ressources to appear automatically in the finder you normally have to be in the same LAN which is not the case if you connect via VPN. If your Mac Mini is running OS X Server you should be able to configure Wide Area Bonjour which can be activated in your DNS configuration. In addition to that, in you VPN network configuration on the client you should use your server DNS address (an not the one of your ISP). Only your DNS on your server knows about your local services and can broadcast them to your client. It's what I believe the MobileMe service does when you configure it appropriately.
    That should be the theory. However, I didn't manage to get this into work anyway. I wonder if anyone has.
    - Juergen

  • Kerberos issue when connecting via VPN

    Hi,
    I am have some issues when connecting via VPN.
    The following kdc log is issued when I log via VPN
    May 02 12:12:21 ATHENA.MYDOMAIN.LAN krb5kdc[163](info): DISPATCH: repeated (retransmitted?) request from 192.168.2.5, resending previous response
    May 02 12:12:21 ATHENA.MYDOMAIN.LAN krb5kdc[163](info): TGS_REQ (7 etypes {18 17 16 23 1 3 2}) 192.168.2.5: UNKNOWN_SERVER: authtime 1146535939, [email protected] for ldap/[email protected], Server not found in Kerberos database
    I also have a system log May 2 12:12:21 ATHENA DirectoryService[41]: GSSAPI Error: Miscellaneous failure (Server not found in Kerberos database)
    This logs only happen while logging through VPN.
    Any idea?
    Cheers
    Ben

    Hi,
    When using your VPN are yo using Terminal LIcense or Remote Desktop Connection?
    Please do the following to save form settings:
    1. Only 1 module should be open when using form settings.
        Close other modules that doesn't need.
    2. Close the module after changed. To make sure the settings are saved.
    3. Always close all the module before exiting SBO program, use the click FIle and Exit habit.
    4. Terminal Licensing should be use when connecting remotely.
    Thanks.
    Clint

  • Unable to send out emails via outlook express since 06/29/2010

    Task '[email protected]" - Sending' reported error (0x80042109) : 'Outlook is unable to connect to your outgoing (SMTP) e-mail server. If you continue to receive this message, contact your server administrator or Internet service provider (ISP).'        This is a copy/paste of error message from Office Outlook  2003
    Our household has been unable to "send" outgoing emails since 06/29/2010.  This includes a wireless laptop and a PC. We both lost the ability to send emails same day.  We changed NOTHING and did not share emails with each other that would have corrupted our system. During this time I have had 2 Verizon techs dance around in the PC doing all the same things I did as well as what  the automated assistant did.  The last tech said the Outlook Express 6.0 was corrupted, and to unistall it and then reinstall;  this time 2 hours later, I think he just gave up).  That did not work either.  I tried using the Outlook Office and still got an error message for outging. Everything is set up as it was when it was working until 06/29/2010.  I was told that there was a new server being installed and that things wold be working by 07/02/2010... I have tried taking down the firewall, turning off virus protection (McAfee), changing from outgoing.yahoo.verizon.net to just outgoing.verizon.net, checking boxes, unchecked boxes. SMPT is set to 587.  We get incoming fine.  I hate using the "Verizon email site" as too much monkey motion to get to mail, but that's what we have been doing.  I even tried setting up a GMail account, again got mail still could not send.  Any ideas?

    Thank you for your response!  I even tried sending an email via dos prompt  with Telnet, got past "HELO", but when trying to get a  "RCPT TO"  (using outgoing.yahoo.verizon.net)  I got an "authorization required" response and then was dropped.  I have been passed around without a solution. I am about ready to change ISP, but really hate to as most of the time (years now) this has been a decent ISP. If Verizon is having a problem just say so, I can handle it, honesty would be nice, refreshing and not wasting so much of my time as well as the techs!

  • Cannot send email via Hotmail through port 587 with Secure Connection (SSL) set

    Something is blocking my attempts to send email (with Outlook Express) via my hotmail.com account. The error I receive is as follows:
    Your server has unexpectedly terminated the connection. Possible causes for this include server problems, network problems, or a long period of inactivity. Account: 'Hotmail', Server: 'smtp.live.com', Protocol: SMTP, Port: 587, Secure(SSL): Yes, Error Number: 0x800CCC0F
    When Hotmail.com first changed over to a POP3 server (Sept 2009), I could send emails through them using port 587, which they require. But then something happened, with no changes on my part, to disable my ability to send.
    I have checked and rechecked my Outlook Express account settings. I can send email through another third-party mail account (at 1&1 Internet.com) using port 587, which does not require setting SSL to yes. I can also ping the Hotmail SMTP server via port 587 and receive a response from it.
    I connect to Verizon DSL via a Westell 327W modem/router. Clearly it is not blocking port 587 without SSL. Does it have the capability to block SSL traffic? Or is the Verizon server the culprit, not allowing emails to be sent via Hotmail.com?
    Two different computers on my LAN have the same problem sending emails via Hotmail.com. I have tried everything the Hotmail people have suggested; at this point they think it is an ISP problem, hence this post. This problem doesn't make sense to me and is driving me crazy. Can anyone help me with this?
    Thanks.

    You can still have your reply address set to your hotmail address. And you don't have to really remember to do anything. Configure your client for the HOTMAIL account with Verizon's outgoing server. It will automatically send via Verizon. You don't reveal your verizon.net address, you are just using their server to transmit.
    If a forum member gives an answer you like, give them the Kudos they deserve. If a member gives you the answer to your question, mark the answer as Accepted Solution so others can see the solution to the problem.
    "All knowledge is worth having."

  • Unable to access gateway and DNS via VPN (L2TP) with Snow Leopard Server

    Summary:
    After rebooting my VPN server, i am able to establish a VPN (L2TP) connection from outside my private network. I am able to connect (ping, SSH, …) the gateway only until the first client disconnects. Then i can perfectly access all the other computers of the private network, but i cannot access the private IP address of the gateway.
    Additionally, during my first VPN connection, my DNS server, which is on the same server, is not working properly with VPN. I can access it with the public IP address of my gateway. I can access it from inside my private network. A port scan indicates me that the port 53 is open, but a dig returns me a timeout.
    Configuration:
    Cluster of 19 Xserve3.1 - Snow Leopard Server 10.6.2
    Private network 192.168.1.0/255.255.255.0 -> domain name: cluster
    -> 1 controller, which act as a gateway for the cluster private network, with the following services activated:
    DHCP, DNS, firewall (allowing all incoming traffic for each groups for test purposes), NAT, VPN, OpenDirectory, web, software update, AFP, NFS and Xgrid controller.
    en0: fixed public IP address -> controller.example.com
    en1: 192.168.1.254 -> controller.cluster
    -> 18 agents with AFP and Xgrid agent activated:
    en1: 192.168.1.x -> nodex.cluster with x between 1 and 18
    VPN (L2TP) server distributes IP addresses between 192.168.1.201 and 192.168.1.210 (-> vpn1.cluster to vpn10.cluster). Client informations contain the private network DNS server informations (192.168.1.254, search domain: cluster).
    _*Detailed problem description:*_
    After rebooting the Xserve, my VPN server works fine except for the DNS. My client receives the correct informations:
    Configure IPv4: Using PPP
    IPv4 address: 192.168.1.201
    Subnet Mask:
    Router: 192.168.1.254
    DNS: 192.168.1.254
    Search domain: cluster
    From my VPN client, i can ping all the Xserve of my cluster (192.168.1.1 to 18 and 192.168.1.254). If i have a look in Server Admin > Settings > Network, i have three interfaces listed: en0, en1 and ppp0 of family IPv4 with address 192.168.1.254 and DNS name controller.cluster.
    The DNS server returns me timeouts when i try to do a dig from my VPN client even if i am able to access it directly from a computer inside or outside my private network.
    After i disconnect, i can see in Server Admin that the IP address of my ppp0 interface has switch to my public IP address.
    Then i can always establish a VPN (L2TP) connection, but the client receives the following informations:
    Configure IPv4: Using PPP
    IPv4 address: 192.168.1.202
    Subnet Mask:
    Router: (Public IP address of my VPN server)
    DNS: 192.168.1.254
    Search domain: cluster
    From my VPN client, i can access all the other computers of my network (192.168.1.1 to 192.168.1.18) but when i ping my gateway (192.168.1.254), it returns me timeouts.
    I have two "lazy" solutions to this problem: 1) Configure VPN and DNS servers on two differents Xserve, 2) Put the public IP address of my gateway as DNS server address, but none of these solutions are acceptable for me…
    Any help is welcome!!!

    I would suggest taking a look at:
    server admin:vpn:settings:client information:network route definitions.
    as I understand your setup it should be something like
    192.168.1.0 255.255.255.0 private.
    at least as a start. I just got done troubleshooting a similar issue but via two subnets:
    http://discussions.apple.com/thread.jspa?threadID=2292827&tstart=0

  • Do I need to run DNS on a colo server being accessed remotely via VPN?

    My Mac Mini Server is located in a colo site. We generally use it for Web, email and a couple of application-specific services. It has a dedicated IP address. We have a separate DNS service we use to point to the domains on the server located remotely from the server. Forward and reverse lookups work fine from the server, even though the local DNS service is turned off.
    However, we now have a couple of things we want to access remotely on the server via VPN (for example, some files via AFP). The firewall blocks remote AFP requests (using the built-in firewall, not a separate box). We can connect via VPN without problems. However, AFP does not work. If I allow AFP in the firewall and try to connect, no problems at all.
    Since the Mini is located by itself and will never likely have anything connected to a "local network" (never running DHCP, etc.), there generally doesn't seem to be a need to run DNS on the server.
    I suspect the problem is that when you VPN into the server you are on its "local network", whatever that means, so the DNS does not resolve since the local DNS service is not running. However, I am not positive of this.
    Must we run local DNS? Does it have to mirror the remote DNS that we currently reference? Can we somehow "reference" the local DNS from VPN clients trying to access local services?
    I hope this question makes some sense.

    Bear with me please....
    The Mac Mini is in a data center on a shelf, getting a direct connection to the Internet via ethernet with a fixed IP address (under the covers, I suspect that the data center is using some sort of router or switch, but I am not paying for a hardware firewall or other gateway). There is no local network for the Mini. It is not running DHCP, not handing out NAT addresses, etc. DNS is currently off. Rather than using the local DNS, the Mini is resolving its DNS needs with a DNS server located at another site, over the Internet. This seems to work fine (i.e., changeip confirms it is working and services seem to work).
    I am currently using the software firewall built into SLS.
    I want to turn on VPN so that remotely located computers can access services on the Mini without having to make the services visible through the firewall.
    I am able to connect devices via VPN with little difficulty (iPhones, Macs, etc.). However, when I try to access services (let's use AFP as an example), I cannot access them UNLESS they are allowed through the firewall. This tells me that I am not seeing the services through the VPN, but rather through the Internet directly.
    What I meant by "local network" is that the VPN allocates local IP addresses when devices log into the VPN service (10.0.x.x). There is no DHCP allocating these addresses, just VPN.
    My question is: why can I not see the services on the Mini blocked by the firewall when successfully logged into VPN on the server? Isn't the whole point of the VPN to gain access to services behind the firewall?
    I am guessing (with no particular information to support my thesis) that somehow without DNS running on the Mini, VPN clients are unable to access services on the Mini. I do not know for sure, however, if this is the problem. If it IS a problem, then the question is whether I should completely copy the DNS entries from the remote DNS server to the Mini and start the service. Will that solve the issue? Create conflicts with the DNS (since it is now located on both a remote service and on the Mini)? It certainly will create a maintenance headache since now I will have to maintain the DNS in both places.
    I am hesitant to migrate all of my DNS services to the Mini (because I will also have to go to the domain registrars to change where they point, etc.) to eliminate the remote one. And I am not sure it will solve this problem anyway.
    Sorry for all of the typing!

Maybe you are looking for