Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    (yet another) IPsec throughput help request

    Scheduled Pinned Locked Moved IPsec
    21 Posts 4 Posters 2.1k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M
      michmoor LAYER 8 Rebel Alliance @SpaceBass
      last edited by

      @SpaceBass Intel NICs?

      Firewall: NetGate,Palo Alto-VM,Juniper SRX
      Routing: Juniper, Arista, Cisco
      Switching: Juniper, Arista, Cisco
      Wireless: Unifi, Aruba IAP
      JNCIP,CCNP Enterprise

      S 1 Reply Last reply Reply Quote 0
      • S
        SpaceBass @michmoor
        last edited by

        @michmoor
        thanks for the continued troubleshooting help!

        US - intel bare metal
        Europe - VirtIO, host NIC in Intel

        P 1 Reply Last reply Reply Quote 0
        • P
          pete35 @SpaceBass
          last edited by

          @SpaceBass

          You may try to adjust your MTU/MSS Settings on both sides equally to exactly these numbers here:

          cb49bff4-31a9-43bc-b70d-bd1e2f2e170f-image.png

          <a href="https://carsonlam.ca">bintang88</a>
          <a href="https://carsonlam.ca">slot88</a>

          S 1 Reply Last reply Reply Quote 0
          • S
            SpaceBass @pete35
            last edited by

            @pete35 I dont (currently) use an interface for ipsec

            M P 2 Replies Last reply Reply Quote 0
            • M
              michmoor LAYER 8 Rebel Alliance @SpaceBass
              last edited by

              @SpaceBass Do you have any Cryptographic Acceleration? Is it on?

              Firewall: NetGate,Palo Alto-VM,Juniper SRX
              Routing: Juniper, Arista, Cisco
              Switching: Juniper, Arista, Cisco
              Wireless: Unifi, Aruba IAP
              JNCIP,CCNP Enterprise

              S 1 Reply Last reply Reply Quote 0
              • S
                SpaceBass @michmoor
                last edited by

                @michmoor AES-NI, yes it is active on both pfSense machines

                1 Reply Last reply Reply Quote 0
                • P
                  pete35 @SpaceBass
                  last edited by

                  @SpaceBass

                  you can try to set MSS Clamping under system/advanced/firewall&Nat

                  a396fc11-82a3-41bd-aa89-1837acbd783f-image.png

                  Why dont you use routed vti?

                  <a href="https://carsonlam.ca">bintang88</a>
                  <a href="https://carsonlam.ca">slot88</a>

                  1 Reply Last reply Reply Quote 0
                  • N
                    NOCling
                    last edited by

                    For Tunnel mode MSS 1328 is most effective:
                    https://packetpushers.net/ipsec-bandwidth-overhead-using-aes/

                    Netgate 6100 & Netgate 2100

                    S 1 Reply Last reply Reply Quote 0
                    • S
                      SpaceBass @NOCling
                      last edited by SpaceBass

                      @NOCling said in (yet another) IPsec throughput help request:

                      For Tunnel mode MSS 1328 is most effective:
                      https://packetpushers.net/ipsec-bandwidth-overhead-using-aes/

                      WOAH! Massive difference (in only one direction)...

                      From US -> Europe

                      [SUM]   0.00-10.00  sec   252 MBytes   211 Mbits/sec  9691             sender
                      [SUM]   0.00-10.20  sec   233 MBytes   192 Mbits/sec                  receiver
                      

                      Europe -> US

                      [SUM]   0.00-10.20  sec  22.0 MBytes  18.1 Mbits/sec    0             sender
                      [SUM]   0.00-10.00  sec  20.5 MBytes  17.2 Mbits/sec                  receiver
                      
                      1 Reply Last reply Reply Quote 0
                      • N
                        NOCling
                        last edited by

                        Nice, but now you have to find a way to the paring jungle how it will work fast on both ways.
                        Looks like US -> EU runs a other way than EU -> US.

                        We talk about that, in our last meeting and the solution is not easy.
                        One Point is to use a Cloud Service Provider he is present on both sides and you can use the interconnect between this cloud instances.

                        Netgate 6100 & Netgate 2100

                        S 1 Reply Last reply Reply Quote 0
                        • S
                          SpaceBass @NOCling
                          last edited by

                          @NOCling and unfortunately my success was very short-lived ...
                          It looks like iperf3 traffic is still improved, but I'm moving data at 500kB/s - 1.50MB/s

                          M 1 Reply Last reply Reply Quote 0
                          • M
                            michmoor LAYER 8 Rebel Alliance @SpaceBass
                            last edited by

                            @SpaceBass if you temp switch to Wireguard does the issue follow?
                            If it does it may not be MTU related.

                            Firewall: NetGate,Palo Alto-VM,Juniper SRX
                            Routing: Juniper, Arista, Cisco
                            Switching: Juniper, Arista, Cisco
                            Wireless: Unifi, Aruba IAP
                            JNCIP,CCNP Enterprise

                            1 Reply Last reply Reply Quote 0
                            • N
                              NOCling
                              last edited by

                              How do you move your Data?
                              SMB is a very bad decision for high latency ways, you need rsync or other wan optimized protocols.

                              Netgate 6100 & Netgate 2100

                              S 1 Reply Last reply Reply Quote 0
                              • S
                                SpaceBass @NOCling
                                last edited by

                                @NOCling said in (yet another) IPsec throughput help request:

                                How do you move your Data?

                                rsync - have tried both an NFSv4 mount and over ssh (for testing purpose)

                                1 Reply Last reply Reply Quote 0
                                • First post
                                  Last post
                                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.