Disable Tunnel Acceleration
Focus
Focus

Disable Tunnel Acceleration

Table of Contents
End-of-Life (EoL)

Disable Tunnel Acceleration

Disable tunnel acceleration for GRE, VXLAN, and GTP-U tunnels to troubleshoot.
By default, supported firewalls perform tunnel acceleration to improve performance and throughput for traffic going through GRE tunnels, VXLAN tunnels, and GTP-U tunnels. Tunnel acceleration provides hardware offloading to reduce the time it takes to perform flow lookups and allows the tunnel traffic to be distributed more efficiently based on the inner traffic.
GRE and VXLAN tunnel acceleration is supported on PA-3200 Series firewalls and PA-7000 Series firewalls with PA-7000-100G-NPC-A and PA-7050-SMC-B or PA-7080-SMC-B. You can disable tunnel acceleration to troubleshoot. When you disable tunnel acceleration, you are doing so for GRE, VXLAN, and GTP-U tunnels simultaneously.
There is no performance impact for GRE traffic when disabling tunnel acceleration if no tunnel content inspection (TCI) policies are being used.
  1. Select DeviceSetupManagement and edit General Settings.
  2. Deselect Tunnel Acceleration to disable it.
  3. Click OK.
  4. Commit.
  5. Reboot the firewall.
  6. (Optional) Verify status of tunnel acceleration.
    1. Access the CLI.
    2. > show tunnel-acceleration
      System output is Enabled or Disabled. Additional status and reason for GTP-U only:
      • Disabled—GTP-U tunnel acceleration is not supported on firewall model or GTP Security is disabled.
      • Error (TCI with GTP-U configured unexpectedly)—TCI with GTP-U protocol is configured when Tunnel Acceleration is enabled.
      • Enabled—Tunnel Acceleration is enabled; GTP-U Tunnel Acceleration is not running yet. GTP Security is enabled, but yet to reboot.
      • Installed—GTP-U Tunnel Acceleration is running.