Zscaler supports up to 1 Gbps per GRE tunnel when internal endpoint addresses are not source-NATed, so one tunnel cannot satisfy a 1.5 Gbps target. The GRE overview documents that limit, and Zscaler’s traffic-forwarding reference architecture states that throughput above 1 Gbps can be handled by adding GRE tunnels. Therefore, two GRE tunnels are the minimum capacity set among the choices. Traffic distribution must preserve flow or source consistency, and Zscaler notes that additional GRE tunnels should originate from unique public IP addresses to avoid repeated authentication and application-session issues. Path MTU Discovery does not increase the one-tunnel ceiling. Two IPsec tunnels provide only 800 Mbps in aggregate because the same reference architecture specifies 400 Mbps per IPsec tunnel. A single IPsec peer is consequently even further below the requirement.
Contribute your Thoughts:
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit