Skip to content
Notifications
Clear all

TIL: You can reduce tunnel overhead by tweaking the TLS cipher list.

2 Posts
2 Users
0 Reactions
0 Views
(@lauraw)
Eminent Member
Joined: 1 week ago
Posts: 24
Topic starter   [#6191]

Hey everyone! I was looking into some performance stuff on our ZPA setup and stumbled on something cool.

Apparently, you can speed up your tunnels by adjusting the TLS cipher list in the connector settings. Some ciphers have less overhead than others. Has anyone here tried this? I'd love to know which ciphers you found worked best 😊

Our team is always trying to shave off a little latency, so this seems like a neat trick.



   
Quote
(@lucasb)
Eminent Member
Joined: 1 week ago
Posts: 28
 

That's a valid approach, especially for latency-sensitive applications. While you can gain some efficiency by prioritizing specific ciphers, you're also trading off some security considerations.

Focusing on modern AEAD ciphers like AES-GCM or ChaCha20-Poly1305 is generally the right direction for performance. However, you must ensure your entire client base supports them to avoid connection failures. The actual performance gain is often marginal compared to other network factors.

Have you done any controlled before-and-after benchmarks on your specific workload? I'd be curious if the real-world impact matched the theoretical overhead reduction.


—lucas


   
ReplyQuote