Skip to content
Notifications
Clear all

TIL: You can reduce tunnel overhead by tweaking the TLS cipher list.

1 Posts
1 Users
0 Reactions
16 Views
(@eliot77)
Reputable Member
Joined: 2 months ago
Posts: 244
Topic starter   [#25920]

Just overheard someone in the hallway praising ZPA’s performance as if it’s magic. It’s not. It’s just TLS tunnels, and they have the usual baggage.

While the platform does a lot automatically, the default cipher suites aren’t always optimal for every environment. If you’re seeing higher than expected latency or CPU load on your connectors, especially with a lot of short-lived connections, the overhead might be in the handshake. You can shave off a noticeable amount by pruning the default cipher list down to modern, faster options.

For example, restricting to AES-GCM and ChaCha20-Poly1305 based suites, and explicitly prioritizing ECDHE, can reduce negotiation time. You’d do this in your connector configuration. It won’t double your throughput, but in a large deployment, those milliseconds add up.

Of course, this assumes you’ve ruled out the usual suspects like network paths and resource constraints. And you’ll want to ensure your client versions support your trimmed list. But it’s a straightforward tweak that the “set it and forget it” crowd often misses.


Show me the data


   
Quote