Reset Search
 

 

Article

TSB44404 - Important Information on How to Increase Remote Users on a Pulse Connect Secure Appliance

« Go Back

Information

 
Last Modified Date3/20/2020 6:49 PM
Legacy Id
Product AffectedPulse Connect Secure (PCS)
Alert Description
Dear Customer,

This bulletin announces the Product Support Notification (PSN) for the following:

TSB44404 - How to Increase Remote Users on a Pulse Connect Secure Appliance
 
Description:
 
In response to the Corona Virus (COVID-19) pandemic, a significant number of users are required to work from home. This notification offers guidance to Pulse Connect Secure (PCS) administrators on how to optimize the number of remote users on a PCS appliance. The purpose of this notification is to provide guidance on how to more assuredly increase users on a PCS appliance in order to minimize the likelihood of an outage due to overloading appliance capacity.

 
Solution
Please review the following Frequently Asked Questions for useful information on managing the load on your PCS appliance 

1. What is the maximum capacity of my PCS Appliance? 

Beyond license restriction, the maximum number of users that your appliance can support depends on several environmental factors including: 
  • Device throughput.
  • Average packet size (With less packet sizes, more PCS CPU is spent on analyzing the packets and hence less throughput).
  • Cipher size, FIPS ON.
  • VLANs and virtual ports.
  • Number of ACLs.
  • Number of Roles.
  • Multicast traffic enabled under user role > VPN tunneling options. 
  • CPUs, Memory, and other system characteristics.
  • Encryption algorithm type and key size configured.
  • Network latency between the authentication servers and backend applications.
  • Complexity of Host Checker polices and role mapping rules.
  • VPN Tunneling mode (ESP or SSL).
  • Clustering synchronizations for configs and sessions. 
For “sample” data on the maximum user count and throughput for various PSA appliances, please visit KB40057 and the PCS datasheet    

2. How can I optimize my PCS appliance for more capacity?  

If your PCS appliance is approaching the maximum limit, you may notice CPU spikes on the Admin UI overview graph, throughput that are nearing the capacity of the appliance, or slow performance during peak usage.  Please use the following guidelines to optimize the appliance utilization: 

Throughput Optimization :
  • Consider using spit-tunneling to exclude internet and high bandwidth voice traffic outside tunnel. Please refer section About Split Tunneling Role Options in admin guide .
  • Minimize or avoid enabling multi-cast traffic. 
  • If using Active/Passive cluster, consider switching to Active/Active cluster. See KB44398 for more information. 
  • If using an Active/Active cluster, consider adding more appliances to the cluster. You can add up to 4 appliances in a PSA 7000 Active/Active cluster. 
  • Limit the use of high bandwidth applications such as HTML5 RDP. Alternatively, you can use the Java RDP for remote desktops. Refer KB41005 for HTLML5 high CPU issue and KB41060 for Premier JAVA RDP 
  • Convert your clusters to standalone and have users connect to individual nodes to divide load.
  • Wireless adapters such as the ones below are known to provide better throughput.
  1. Asus ac-56
  2. TP-Link Archer T9UH AC1900 High Gain Wireless Dual Band USB Adapter
 Configuration Optimizations: 
  • Review and optimize your Host Checker policies.
  • If “IP Address Filter” (Under System -> Network -> VPN Tunneling) & many Static IP Address Pool (Users -> Resource Policies -> VPN Tunneling -> Connection Profiles) are configured, please ensure that the Pool Matching the “IP Address Filter” is at the top of the list. Else, it can result in the following side-effects, 
    •  Huge Latencies.
    •  User Connection Drops.
    •  Users unable to connect/obtain IP Addresses.
    •  ESP connections falling back to SSL.
  • Ensure that VPN tunnels are using ESP mode. Refer page 631 admin Guide
3. How can I tell if my PCS appliance is under high load?  
  • Check system and event logs for critical messages .
  • Review device graphs to see if your appliance’s throughput is within the specified limits. Please check KB43684 for more information on Throughput calculation
  • Check for High CPU, refer KB15832 
4. What logs should I provide when reporting a performance issue?  

Refer to KB44397 for logs required for troubleshooting performance issues  

Note: Up-to-date information on this PSN is available at TSB44404 
 
Pulse Secure Support is available 24X7 at: +1-844-751-7629 (Toll free, US & Canada), +1-408-300-9668 (Other Countries). 


 
Implementation
Alert Type 
Related Links
Attachment 1 
Attachment 2 

Feedback

 

Was this article helpful?


   

Feedback

Please tell us how we can make this article more useful.

Characters Remaining: 255