How to troubleshoot slow VPN performance: latency, packet loss and MTU
The internet works normally.
Then the user connects to the corporate VPN.
Suddenly:
Applications become slow.
Remote desktop freezes.
File transfers stall.
Websites load slowly.
Sessions disconnect.
Or some applications stop working completely.
Users often conclude:
“The VPN is broken.”
But a VPN introduces additional networking layers.
A typical remote connection might look like:
User → WiFi → ISP → Internet → VPN Gateway → Firewall → Corporate Network → Application
A problem anywhere along that path can affect VPN performance.
This guide explains how to troubleshoot slow or unstable VPN connections and how latency, packet loss, MTU, routing, WiFi, firewalls and internet circuits can influence remote user performance.
Why Is My VPN So Slow?
Common causes include:
- High latency
- Packet loss
- Jitter
- Congestion
- Poor WiFi
- Slow home internet
- VPN gateway load
- Firewall load
- Encryption overhead
- Inefficient routing
- MTU problems
- Fragmentation
- DNS
- Application performance
The first goal should be:
Determine whether the VPN is actually the cause or whether the underlying network is already degraded.
What Does a VPN Change About Network Traffic?
A VPN creates an encrypted tunnel between endpoints.
That can add:
- Encryption
- Encapsulation
- Additional routing
- Additional firewall processing
The traffic may also take a longer route than direct internet traffic.
These factors can affect performance.
How Do You Know if the VPN Is the Problem?
Compare the user experience:
Without VPN
versus:
With VPN
where organizational security policy permits that comparison.
If performance is poor both ways, the underlying connection may be the main problem.
If performance is healthy without the VPN and deteriorates only after connecting, investigate the VPN path.
Why Does VPN Latency Increase?
VPN traffic may travel through a centralized security or data center location before reaching its destination.
For example:
User in Dallas
→ VPN gateway in New York
→ Cloud application in Texas
That route can introduce unnecessary distance and delay.
What Is VPN Packet Loss?
Packet loss affects VPN traffic just as it affects ordinary network traffic.
The tunnel does not magically eliminate underlying network loss.
If the user's ISP connection loses packets, VPN applications can suffer.
Why Does VPN Keep Disconnecting?
Possible causes include:
- Internet instability
- WiFi interruptions
- Packet loss
- VPN gateway issues
- Firewall behavior
- Session timeout
- Routing changes
- ISP issues
- Device sleep or power events
The important question is:
Did the underlying internet connection fail too?
How Do You Determine Whether the ISP or VPN Is Causing Disconnects?
Correlate both layers.
For example:
VPN disconnects at 2:14 PM.
At the same moment:
Local internet remains healthy.
Latency remains normal.
No packet loss.
That suggests investigating VPN infrastructure.
Now compare:
VPN disconnects at 2:14 PM.
WAN packet loss begins at 2:13 PM.
Internet circuit flaps at 2:14 PM.
That points toward the underlying network.
What Is VPN MTU?
MTU stands for Maximum Transmission Unit.
It represents the largest packet size that can be sent across a network path without requiring fragmentation.
VPN encapsulation adds overhead.
That can make previously acceptable packet sizes too large for the tunnel path.
How Can MTU Cause VPN Problems?
MTU issues can create strange symptoms:
- Ping works
- Small requests work
- Large transfers fail
- Login begins but hangs
- Remote desktop connects but stalls
- Websites partially load
- Some applications work and others fail
Cisco's current 2026 DMVPN troubleshooting guidance specifically identifies MTU, MSS and fragmentation as possible causes when small packets work but larger TCP application traffic hangs or fails.
What Is MSS?
MSS stands for Maximum Segment Size.
It controls how much TCP payload can be carried in a segment.
VPN environments may adjust MSS to account for tunnel overhead and avoid fragmentation.
Cisco specifically recommends evaluating MTU and MSS when VPN encapsulation causes packets to exceed the supported path size.
What Is Fragmentation?
Fragmentation occurs when a packet is too large for part of the network path and must be divided.
In some environments:
- Fragmentation creates inefficiency
- Packets are dropped
- Applications stall
This can produce the classic symptom:
Ping works, application fails.
Why Does Ping Work but My VPN Application Fails?
Because small diagnostic packets may cross the tunnel successfully while larger application packets encounter:
- MTU limitations
- Fragmentation
- Firewall rules
- Application port issues
Cisco lists exactly this pattern among common MTU and fragmentation symptoms.
How Do You Test VPN MTU?
Authorized network engineers can use controlled packet size testing to determine whether larger packets fail.
Cisco recommends extended ping testing with the Don't Fragment setting and gradually increasing packet size when investigating MTU problems in applicable environments.
The exact commands and safe values depend on the platform and architecture.
Can WiFi Make a VPN Slow?
Absolutely.
The VPN may simply make an already unstable connection more noticeable.
Test:
Wired
versus:
WiFi
If wired VPN performance is healthy while WiFi performance is poor, investigate the wireless environment.
Can Home Internet Cause VPN Problems?
Yes.
Remote users depend on:
- Local ISP
- WiFi
- Router
- Modem
- Internet path
Corporate IT may have no control over several of those components.
That is why remote VPN troubleshooting requires separating:
User network
from:
Corporate VPN
from:
Application
Can the Corporate Firewall Cause VPN Performance Problems?
Yes.
Possible causes include:
- CPU load
- Memory pressure
- Encryption processing
- Interface congestion
- VPN tunnel load
- Security inspection
- Routing
- Configuration
Review firewall health during the incident.
Can VPN Concentrators Become Overloaded?
Yes.
Centralized VPN infrastructure has finite resources.
Potential symptoms include:
- Slow authentication
- Poor throughput
- High latency
- Disconnects
- Application delays
Compare performance across multiple remote users.
If many users experience degradation at the same time, investigate shared infrastructure.
Can DNS Cause VPN Problems?
Yes.
VPNs often change DNS behavior.
Possible problems include:
- Internal DNS unavailable
- Split DNS configuration
- Incorrect DNS server
- Slow DNS
- Routing toward DNS server
If application access fails by hostname but works by IP, DNS deserves investigation.
What Is Split Tunneling?
Split tunneling allows some traffic to use the corporate VPN while other traffic goes directly to the internet.
Full tunnel configurations send more traffic through the VPN.
Each design has security and operational tradeoffs.
The appropriate configuration should follow organizational security policies.
Can Full Tunnel VPN Make Cloud Applications Slower?
Potentially.
If all traffic is routed through a distant corporate VPN gateway, cloud application traffic may take a longer path than necessary.
That additional path can increase latency.
This does not automatically mean full tunnel design is wrong.
Security and compliance requirements may justify it.
The architecture should be intentional.
How Do You Troubleshoot VPN Performance Step by Step?
Step 1: Determine Scope
One user?
One location?
Everyone?
One application?
Every application?
Step 2: Record Exact Time
Correlate the user complaint with:
- VPN logs
- Firewall logs
- WAN monitoring
- Application logs
Step 3: Test Underlying Internet
Check:
- Latency
- Packet loss
- Jitter
- Availability
Step 4: Compare Wired and WiFi
Eliminate wireless variables.
Step 5: Compare VPN and Non VPN Performance
Where permitted.
Step 6: Check VPN Gateway
Review:
- CPU
- Memory
- Sessions
- Interface utilization
- Tunnel health
Step 7: Check Routing
Determine whether traffic is taking an inefficient path.
Step 8: Test MTU and Fragmentation
Particularly when small traffic works and large traffic fails.
Step 9: Test DNS
Ensure internal and external names resolve correctly.
Step 10: Review Historical Data
Was the underlying WAN degraded during the VPN complaint?
Why Are VPN Problems Often Misdiagnosed?
Because users experience the final application.
They do not see the network path.
A user says:
“VPN is slow.”
The actual cause may be:
Weak WiFi
ISP packet loss
Corporate firewall
VPN routing
MTU
Application
The support team's job is to isolate the layer.
Why Is Historical Monitoring Valuable for VPN Troubleshooting?
Suppose:
10:14 AM
Remote user reports VPN freezing.
10:13 AM
Branch WAN latency increases.
10:14 AM
Packet loss reaches 5%.
10:17 AM
Network recovers.
Now there is strong evidence that the VPN symptom was correlated with network degradation.
Without historical monitoring, the investigation may begin after everything returns to normal.
How Does VPN Troubleshooting Fit the ADAM Fault Isolation Model?
The path becomes:
Endpoint → Local Network → ISP → VPN → Firewall → Corporate Network → Application → History
Ask at each boundary:
Is this layer healthy?
Where does performance change?
What Is the ADAM Pulse Approach to VPN Troubleshooting?
ADAM Pulse can provide visibility into the network infrastructure surrounding VPN performance.
That can help answer:
Was the business location online?
Was the gateway healthy?
Was the firewall healthy?
Was the WAN circuit stable?
Was packet loss occurring?
Was latency increasing?
Did the condition happen before?
Combined with VPN platform diagnostics, this creates a much stronger troubleshooting picture.
Stop Calling Every Remote Performance Problem a VPN Problem
VPN is one part of the path.
The real troubleshooting question is:
Where Does Performance Deteriorate?
User connection?
ISP?
Tunnel?
Firewall?
Corporate network?
Application?
ADAM Pulse provides managed network monitoring designed to help USA Telecom customers isolate the network conditions surrounding VPNs, cloud applications and distributed users.
Test the underlying network.
Test the tunnel.
Test the application.
Correlate the evidence.
Learn more about ADAM Pulse and talk with USA Telecom about network monitoring, VPN troubleshooting and managed network operations.
Frequently asked questions
What Does a VPN Change About Network Traffic?
A VPN creates an encrypted tunnel between endpoints. That can add: The traffic may also take a longer route than direct internet traffic.
How Do You Know if the VPN Is the Problem?
Compare the user experience: versus: where organizational security policy permits that comparison.
Why Does VPN Latency Increase?
VPN traffic may travel through a centralized security or data center location before reaching its destination. For example: User in Dallas
What Is VPN Packet Loss?
Packet loss affects VPN traffic just as it affects ordinary network traffic. The tunnel does not magically eliminate underlying network loss. If the user's ISP connection loses packets, VPN applications can suffer.
What Is VPN MTU?
MTU stands for Maximum Transmission Unit. It represents the largest packet size that can be sent across a network path without requiring fragmentation. VPN encapsulation adds overhead.
How Can MTU Cause VPN Problems?
MTU issues can create strange symptoms: Cisco's current 2026 DMVPN troubleshooting guidance specifically identifies MTU, MSS and fragmentation as possible causes when small packets work but larger TCP application traffic hangs or fails.
What Is MSS?
MSS stands for Maximum Segment Size. It controls how much TCP payload can be carried in a segment. VPN environments may adjust MSS to account for tunnel overhead and avoid fragmentation.
What Is Fragmentation?
Fragmentation occurs when a packet is too large for part of the network path and must be divided. In some environments: This can produce the classic symptom:
Why Does Ping Work but My VPN Application Fails?
Because small diagnostic packets may cross the tunnel successfully while larger application packets encounter: Cisco lists exactly this pattern among common MTU and fragmentation symptoms.
How Do You Test VPN MTU?
Authorized network engineers can use controlled packet size testing to determine whether larger packets fail. Cisco recommends extended ping testing with the Don't Fragment setting and gradually increasing packet size when investigating MTU problems in applicable environments. The exact commands and safe values depend on the platform and architecture.
Sources
- IETF — RFC 1191: Path MTU Discovery (November 1990). ICMP-based path MTU discovery for IPv4.
- IETF — RFC 8201: Path MTU Discovery for IP version 6 (July 2017, Internet Standard, STD 87).
- IETF — RFC 4821: Packetization Layer Path MTU Discovery (March 2007). The fallback when ICMP is filtered and classic PMTUD black-holes.
- IETF — RFC 792: Internet Control Message Protocol (September 1981, Internet Standard, STD 5). Why devices may rate-limit or deprioritise the ICMP that ping and traceroute depend on.
- Cisco — What Is Network Latency?
- Cisco — Troubleshoot Packet Drops. Congestion, buffer exhaustion and interface errors as drop causes.
A single test from a single location at a single moment rarely proves where a fault sits. Correlate against history, test from more than one point, and preserve timestamped evidence before changing configuration or rebooting equipment.
ADAM Pulse separates VPN concentrator load, path MTU and the underlying circuit so a slow tunnel is not treated as a mysterious application problem.