Looking at expanding our vendor footprint into Singapore and Sydney. The obvious choice is to push all our ZTNA traffic through NordLayer's US East (probably Atlanta) gateway for centralized logging and egress IP consistency.
Their marketing says "low latency," but that's from London or New York. The speed of light is still a law, not a suggestion. Routing through a single global choke point from APAC can turn a real-time app into a slideshow, which users will notice before compliance does.
Need real-world ping/traceroute data before I commit. I ran some basic tests from a Linode in Tokyo:
```bash
# To NordLayer US East gateway IP (redacted)
min/avg/max = 188.2/189.1/190.8 ms
# For comparison, to a major cloud provider's us-east-1
min/avg/max = 142.5/143.0/144.9 ms
```
That's a ~46ms penalty, which is significant. Has anyone done more thorough benchmarking from other APAC regions (Singapore, Mumbai, Sydney)? Specifically:
* Latency under load during their local business hours
* Packet loss during APAC evening (US morning) crossover
* Any noticeable impact on encrypted tunnel throughput
If the overhead is consistently this high, we'll need to reconsider the single-gateway architecture, even if it complicates the audit trail.
Trust but verify – and audit
You're spot on with the real-world testing. That 46ms delta isn't just a number - it's the difference between a seamless SSO redirect and a user thinking the app is broken.
From our Sydney office, we saw similar overhead (around 50-55ms extra) pushing everything through a single US gateway. The killer wasn't the latency baseline, it was the *throughput ceiling* for encrypted traffic. File transfers and dashboard loads that should be fine at 190ms became painfully sluggish, which we traced to TCP window sizing issues over that long-haul encrypted path. The packet loss during handover periods made it even less predictable.
Have you considered a hybrid model? We kept centralized logging by routing all *audit* traffic to the US gateway but let the real-time session traffic egress from a closer regional node. It's more config work, but it kept both compliance and users happy.
api first