Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    New Spectrum Gigabit Internet/Slower Download Speeds Than Expected

    Scheduled Pinned Locked Moved Official Netgate® Hardware
    21 Posts 7 Posters 4.0k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • T
      Tenorbro @rbuseraccount
      last edited by

      @rbuseraccount I haven’t made much progress. I’m not sure of my next step to take. If it’s an appliance issue, the cost associated is a deterrent. The What and How for testing is what I need to understand next.

      M R 2 Replies Last reply Reply Quote 0
      • M
        michmoor LAYER 8 Rebel Alliance @Tenorbro
        last edited by

        @tenorbro if you plug in your computer directly into the cable modem. Your computer gets a public IP. You do a Speedtest. What’s the result?

        Firewall: NetGate,Palo Alto-VM,Juniper SRX
        Routing: Juniper, Arista, Cisco
        Switching: Juniper, Arista, Cisco
        Wireless: Unifi, Aruba IAP
        JNCIP,CCNP Enterprise

        T 1 Reply Last reply Reply Quote 0
        • T
          Tenorbro @michmoor
          last edited by Tenorbro

          @michmoor It’s been a month since I tested with the new modem, but I was receiving the 900+ mbps Down and 35+ mbps Up. So I knew I was received what Spectrum was selling. I plugged my Mac directly into the modem and ran Speedtest.net.

          M 1 Reply Last reply Reply Quote 0
          • M
            michmoor LAYER 8 Rebel Alliance @Tenorbro
            last edited by

            @tenorbro what services do you have running?
            Are you policy routing through a VPN?

            Firewall: NetGate,Palo Alto-VM,Juniper SRX
            Routing: Juniper, Arista, Cisco
            Switching: Juniper, Arista, Cisco
            Wireless: Unifi, Aruba IAP
            JNCIP,CCNP Enterprise

            T 1 Reply Last reply Reply Quote 0
            • T
              Tenorbro @michmoor
              last edited by

              @michmoor My raspberry pie runs Pi-hole and DNS. I have Firewalla monitoring my network. I don’t use a VPN unless I’m outside of my network, and that’s hosted on Firewalla using OpenVPN.

              R 1 Reply Last reply Reply Quote 0
              • R
                rbuseraccount @Tenorbro
                last edited by

                @tenorbro

                I hear you there!
                I never had Traffic Shaping configured and I updated my pfBlockerNG-devel version, but that did nothing....

                1 Reply Last reply Reply Quote 0
                • stephenw10S
                  stephenw10 Netgate Administrator
                  last edited by

                  The 1100 will never pass 1Gbps with firewall+NAT running in a test like that. I would expect it to pass somewhere in the 400-500Mbps given low enough latency. That's with a close to default config. Any additional packages or VPNs etc will reduce that.

                  Steve

                  M 1 Reply Last reply Reply Quote 0
                  • M
                    michmoor LAYER 8 Rebel Alliance @stephenw10
                    last edited by

                    @stephenw10
                    The performance specs have it in the > 900Mbps for routing and 600Mbps for firewall features which i assume NAT or VPN but its difficult to say as that particular metric doesnt really mean anything as its not associated with a package or service function [NAT? Rules? Or NAT and Rules? VPN? IPS?.]
                    I
                    https://shop.netgate.com/products/1100-pfsense

                    Firewall: NetGate,Palo Alto-VM,Juniper SRX
                    Routing: Juniper, Arista, Cisco
                    Switching: Juniper, Arista, Cisco
                    Wireless: Unifi, Aruba IAP
                    JNCIP,CCNP Enterprise

                    S 1 Reply Last reply Reply Quote 0
                    • R
                      rbuseraccount @Tenorbro
                      last edited by

                      @tenorbro

                      That’s exactly what I have running, but I do use a VPN. Of course, I’ve tested with and without the VPN running, so that hasn’t done anything.

                      I “registered” my modem via the Spectrum website last night and it was showing as good. I have yet to open the packaging for their crappy router that came with it. I know that until now, using an ISP’s router wouldn’t have been a factor, but starting to think they’re somehow throttling my bandwidth by 90% until I install—and register—their router. Thoughts?

                      I’m willing to install that, register it, then switch back to my own stuff. I was getting > 200Mbps before uninstalling the older Spectrum router/modem combo.
                      BTW, I run from ISP modem to a beefy custom built PC tower that only has pfSense loaded, then to my WIFI router, then out to my 8-port smart switch, and run everything else from that smart switch.
                      My desktop is plugged directly into the switch with CAT-5e, the rest of my machines run on WiFi.
                      They all get ~25Mbps! 🤦🏼‍♂️

                      T 1 Reply Last reply Reply Quote 0
                      • T
                        Tenorbro @rbuseraccount
                        last edited by

                        @rbuseraccount For what it's worth, I did call Spectrum and sat on the phone with the rep to confirm I was receiving 900+ Down and 35+ Up when I plugged my computer into the EN2251 modem.

                        https://d15yx0mnc9teae.cloudfront.net/sites/default/files/Spectrum%20D3.1%20EMTA%20Data%20Sheet%281%29.pdf

                        1 Reply Last reply Reply Quote 0
                        • T
                          Tenorbro
                          last edited by

                          I also tested for bufferbloat, and it's not great either. My worry is traffic shaping could resolve bufferbloat but reduce speeds. Is this a valid concern?

                          https://www.waveform.com/tools/bufferbloat?test-id=b8563aa8-fea7-4e66-b2f7-0788925b2695

                          M 1 Reply Last reply Reply Quote 0
                          • M
                            michmoor LAYER 8 Rebel Alliance @Tenorbro
                            last edited by

                            @tenorbro screenshot what services you have running on pfsense

                            Firewall: NetGate,Palo Alto-VM,Juniper SRX
                            Routing: Juniper, Arista, Cisco
                            Switching: Juniper, Arista, Cisco
                            Wireless: Unifi, Aruba IAP
                            JNCIP,CCNP Enterprise

                            1 Reply Last reply Reply Quote 0
                            • S
                              SteveITS Galactic Empire @michmoor
                              last edited by

                              @michmoor it also shows 472 and 191 for IMIX Traffic.

                              See
                              https://www.netgate.com/blog/choosing-the-right-netgate-appliance

                              The 1100 shares a 1g connection internally. The switch ports use VLANs to isolate them.

                              (The 2100 has the same CPU but a separate WAN interface.)

                              Also
                              https://forum.netgate.com/topic/145052/sg-1100-throughput/17

                              Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
                              When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
                              Upvote 👍 helpful posts!

                              M 1 Reply Last reply Reply Quote 0
                              • keyserK
                                keyser Rebel Alliance @Tenorbro
                                last edited by

                                @tenorbro I’m sorry to say this, but it’s your pfSense appliance that is limiting you. The SG-1100 tops out at about 300mbps in real life one client firewall (average latency) setups.
                                This is due to the fact it only has one NIC where all ports are connected via a switch and uses VLAN separation to create interfaces.
                                So at about 300mbit the interrupt rate becomes the limiting factor in synthetic real life one client tests.
                                One Nic and One Client always hashes to the same thread, so that thread goes to about 100% of what a CPU core can deliver (= ~300mbps). This explains why you never see a fully loaded CPU, but only 50% (= one thread @ 100%)

                                The synthetic numbers netgate published are “worthless” when it comes to L3 (no firewall, and pure lab optimized conditions) and firewall (pure lab). You need to look at the IMIX numbers, and that is still with more than one client.

                                To make full use of your 1Gbe you need a SG-4100 or higher.

                                Love the no fuss of using the official appliances :-)

                                1 Reply Last reply Reply Quote 2
                                • M
                                  michmoor LAYER 8 Rebel Alliance @SteveITS
                                  last edited by

                                  @steveits yep I see that. You’re right. It’s a platform limitation. Thanks for making me double check.

                                  Firewall: NetGate,Palo Alto-VM,Juniper SRX
                                  Routing: Juniper, Arista, Cisco
                                  Switching: Juniper, Arista, Cisco
                                  Wireless: Unifi, Aruba IAP
                                  JNCIP,CCNP Enterprise

                                  M 1 Reply Last reply Reply Quote 0
                                  • M
                                    mrsunfire @michmoor
                                    last edited by mrsunfire

                                    @Tenorbro Let me give you the advice to go for the 6100 if you have PPPoE connection and/or want to use suricata/snort.

                                    Netgate 6100 MAX

                                    1 Reply Last reply Reply Quote 0
                                    • First post
                                      Last post
                                    Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.