Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Single SMB Server Issue...

    Scheduled Pinned Locked Moved OpenVPN
    5 Posts 2 Posters 610 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • C
      cozzicon
      last edited by

      Hi all,

      I could really use some help here. I'm in the middle of a deployment and every road I go down is blocked with some sort of problem.

      Here's my current issue:

      I've configured a OVPN tun VPN which works. EXCEPT for one windows file server. This server is configured the same as all the other servers on the network.

      The problem is that it is either horrendously slow, or connections to it freeze the file explorer requiring a login/out to reset it.

      Locally the server is fast and behaving normally. And 16 other servers are working fine.

      Has anyone seen this behavior before? I'm at a loss after combing through the configuration of the server for about 3 hours.

      johnpozJ 1 Reply Last reply Reply Quote 0
      • johnpozJ
        johnpoz LAYER 8 Global Moderator @cozzicon
        last edited by

        @cozzicon well generally speaking smb across a wan or vpn connection is never going to be a speedy thing. SMB not really a protocol for large BDP (higher latency)..

        But your ok with the other servers speeds, and they all sit in the same place, on the same network segment? Is it possible this server is using say jumbo frames while the other servers are not? That could prob compound the issues of going across a vpn or wan type connection. Which might not be an issue if local to the servers network.

        An intelligent man is sometimes forced to be drunk to spend time with his fools
        If you get confused: Listen to the Music Play
        Please don't Chat/PM me for help, unless mod related
        SG-4860 24.11 | Lab VMs 2.8, 24.11

        C 1 Reply Last reply Reply Quote 0
        • C
          cozzicon @johnpoz
          last edited by

          @johnpoz Nope.. jumbo frames are disabled.

          johnpozJ 1 Reply Last reply Reply Quote 0
          • johnpozJ
            johnpoz LAYER 8 Global Moderator @cozzicon
            last edited by johnpoz

            @cozzicon and this server on the same network as the other servers that your ok with their performance, and pointing to the same gateway as the other servers?

            That is very odd for sure if all of that is true.

            If was me, I would prob take a network sniff on pfsense (packet capture under diagnostics) take a look at what traffic looks like to and from good server. And then do a sniff with the other servers IP and see what is different? Lots of retrans? Much smaller window size being used? etc..

            This might give us some clue to what the cause of the difference in performance is.

            An intelligent man is sometimes forced to be drunk to spend time with his fools
            If you get confused: Listen to the Music Play
            Please don't Chat/PM me for help, unless mod related
            SG-4860 24.11 | Lab VMs 2.8, 24.11

            C 1 Reply Last reply Reply Quote 0
            • C
              cozzicon @johnpoz
              last edited by

              @johnpoz Yup all of that is true.

              Additionally the server is on the same hyper-v machine that all the other servers are on. So it's not a real world networking problem at all. All the Vms are on the same 10Gb virtual switch.

              The only odd thing about this particular server is that it has a 6TB volume on it.

              Also, this was not a problem with another firewall system that also used openvpn.

              I switched to pfsense because the ipsec support is somehow better- this was trying to resolve an issue with a customer we need to connect to.

              Now I can't get to testing the ipsec link until I resolve this. I've got a $10,000 Checkpoint sitting here which I want to return.

              1 Reply Last reply Reply Quote 0
              • First post
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.