I debugged terrible git clone performance over the VPN at my last company. It turned out our firewall was stripping TCP window scaling by default, which included both our internal GitHub Enterprise instance hosted on AWS and github.com. I collected a bunch of packet traces (tcpdump was sufficient) and eventually got the networking folks to fix the firewall config.
This was a company of a few thousand people with programmers working from home who all must've assumed it was fine to get no more than ~1 Mbps git clone performance. After a few months of putting up with it I finally got tired of the issue and spent 30 minutes tracking down the cause. It still took a week or more of back and forth between me, and the networking and security teams. And it became an ongoing issue as they were allow-listing IP addresses, not fixing the root cause. Why are Cisco firewalls stripping TCP window scaling by default in 2026? I have no idea!
So, yeah...