Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    IPSec preformance

    Scheduled Pinned Locked Moved IPsec
    3 Posts 3 Posters 542 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • S
      stbellcom
      last edited by

      Hello,

      I currently have two Netgate 6100 setup in the lab connected to each other via 2.5gb/s and then running a IPSec VTI tunnel over this connection.

      On each end I also have two pc's with 2.5gb/s running Iperf3 for testing.

      About the best speed I can get is around 1.01 Gbits/sec though the Netgate spec says it should be around 1.8 Gbits/sec for the 6100

      I have tried the recommended settings from this page:

      https://docs.netgate.com/pfsense/en/latest/vpn/performance.html#optimal-encryption-settings

      And a bunch of lesser secure with QAT | AES-NI enabled/disabled without much change.

      Is it realistic to be getting 1.8 Gbits/sec in a lab setup and does anyone have recomendations on which encryption cipher to use to get raw speed though the VPN ?

      Thanks

      D 1 Reply Last reply Reply Quote 0
      • N
        NOCling
        last edited by

        IPsec MB option override IQAT and can result in lower performance.

        Netgate 6100 & Netgate 2100

        1 Reply Last reply Reply Quote 0
        • D
          Deadringers @stbellcom
          last edited by

          @stbellcom said in IPSec preformance:

          Hello,

          I currently have two Netgate 6100 setup in the lab connected to each other via 2.5gb/s and then running a IPSec VTI tunnel over this connection.

          On each end I also have two pc's with 2.5gb/s running Iperf3 for testing.

          About the best speed I can get is around 1.01 Gbits/sec though the Netgate spec says it should be around 1.8 Gbits/sec for the 6100

          I have tried the recommended settings from this page:

          https://docs.netgate.com/pfsense/en/latest/vpn/performance.html#optimal-encryption-settings

          And a bunch of lesser secure with QAT | AES-NI enabled/disabled without much change.

          Is it realistic to be getting 1.8 Gbits/sec in a lab setup and does anyone have recomendations on which encryption cipher to use to get raw speed though the VPN ?

          Thanks

          Can you get the 1.8 Gbps with just NAT?

          i.e. get rid of the IPSEC tunnel, port forward iperf ports and just santiy check that the bandwidth is good for that?

          Would be a good step to test to ensure the path is setup correctly for over gigabit speeds.

          1 Reply Last reply Reply Quote 0
          • First post
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.