What optimal MTU size and encryption settings can optimize Sangfor NGAF SSL VPN throughput?

Newbie343319 Lv1Posted May-01-2026 23:20

Hi, I am currently configuring a Sangfor NGAF for a client and I'm running into some issues with the SSL VPN throughput. The users are reporting significant latency when accessing internal resources remotely. Has anyone found a specific MTU size or encryption setting that optimizes performance for high-bandwidth applications without compromising the security of the tunnel?

By solving this question, you may help 976 user(s).

Posting a reply earns you 2 coins. An accepted reply earns you 20 coins and another 10 coins for replying within 10 minutes. (Expired) What is Coin?

Enter your mobile phone number and company name for better service. Go

Humayun Ahmed Lv4Posted May-06-2026 21:02
  
Use: Split tunnel

Route only:
Internal subnets
Business apps

This alone can improve performance dramatically.
Muhammad Abid Lv2Posted May-06-2026 13:45
  
1. MTU / MSS (most critical)
Set MTU: 1350–1400
Enable MSS clamp: ~1300–1360
Prevents fragmentation → reduces latency

2. Encryption
Use AES-128-GCM (fast + secure)
Avoid heavy ciphers like AES-256-CBC unless required

3. Split Tunnel
Enable split tunneling
Only internal traffic goes via VPN → better performance

4. Check Device Load
Monitor NGAF CPU usage
High CPU = slow VPN
Quick Summary

Most latency issues come from:

Wrong MTU ❌
Heavy encryption ❌
Full tunnel overload ❌

Fix these → performance improves immediately

I Can Help:

Change

Moderator on This Board

1
151
3

Started Topics

Followers

Follow

981
203
99

Started Topics

Followers

Follow

Board Leaders