Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    IPSec is very slow between two pfsense routers

    Scheduled Pinned Locked Moved IPsec
    40 Posts 8 Posters 10.4k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • keyserK
      keyser Rebel Alliance @patrick.pesegodinski
      last edited by

      @patrick-pesegodinski Is this before or after clamping down MSS?
      You are seeing 220mbit which is around 25MB/s (Half your OpenVPN throughput). But I cannot see if you tried a single session iPerf or the default with multiple parallel streams.

      Love the no fuss of using the official appliances :-)

      P 1 Reply Last reply Reply Quote 0
      • P
        patrick.pesegodinski @keyser
        last edited by

        @keyser Test performed without changing the MSS.
        I used the iperf client in Pfsense itself with the default settings.

        M 1 Reply Last reply Reply Quote 0
        • M
          michmoor LAYER 8 Rebel Alliance @patrick.pesegodinski
          last edited by

          @patrick-pesegodinski

          Post your iPerf syntax here so we can understand what you are doing.
          Something along the lines of

          iperf3 -c 192.168.70.26 -P 50 -t 30
          

          Also post for us the before MSS change and after MSS change results.

          Firewall: NetGate,Palo Alto-VM,Juniper SRX
          Routing: Juniper, Arista, Cisco
          Switching: Juniper, Arista, Cisco
          Wireless: Unifi, Aruba IAP
          JNCIP,CCNP Enterprise

          P 1 Reply Last reply Reply Quote 0
          • M
            michmoor LAYER 8 Rebel Alliance @keyser
            last edited by

            @keyser
            I found something in redmine for MTU suggestions.

            https://redmine.pfsense.org/issues/14508

            Firewall: NetGate,Palo Alto-VM,Juniper SRX
            Routing: Juniper, Arista, Cisco
            Switching: Juniper, Arista, Cisco
            Wireless: Unifi, Aruba IAP
            JNCIP,CCNP Enterprise

            1 Reply Last reply Reply Quote 0
            • P
              patrick.pesegodinski @michmoor
              last edited by

              @michmoor Excuse my ignorance, but I'm not familiar with iperf. Which fields do I need to adjust?

              5466484c-126b-4694-8621-f314189cc88b-image.png

              M 1 Reply Last reply Reply Quote 0
              • M
                michmoor LAYER 8 Rebel Alliance @patrick.pesegodinski
                last edited by

                @patrick-pesegodinski
                do not use iperf on the firewall.
                use iperf between your clients (sitting behind your firewall).

                Firewall: NetGate,Palo Alto-VM,Juniper SRX
                Routing: Juniper, Arista, Cisco
                Switching: Juniper, Arista, Cisco
                Wireless: Unifi, Aruba IAP
                JNCIP,CCNP Enterprise

                P 1 Reply Last reply Reply Quote 0
                • P
                  patrick.pesegodinski @michmoor
                  last edited by

                  @michmoor 1f121d95-5939-4faa-a741-3386bf11b08d-TESTE.txt

                  The test with MSS standard.

                  1 Reply Last reply Reply Quote 0
                  • N
                    NOCling
                    last edited by

                    https://packetpushers.net/ipsec-bandwidth-overhead-using-aes/
                    Best MSS for IPsec tunnel Model 1328, if you use transport Mode and a 1500 WAN line, you can use 1372.

                    Netgate 6100 & Netgate 2100

                    P 1 Reply Last reply Reply Quote 0
                    • P
                      patrick.pesegodinski @NOCling
                      last edited by

                      @NOCling hello friend.

                      Thanks for helping me. Your information about MSS with 1328 solved my problem.

                      O 1 Reply Last reply Reply Quote 0
                      • iulianteodorI
                        iulianteodor
                        last edited by iulianteodor

                        What should be the average IPSec VPN speed between two pfsense with 1Gb NIC interface and 1Gbps internet?
                        I've seen all kinds of comments on different forums that the speed could be higher, but I can't do more than that:

                        alt text

                        1 Reply Last reply Reply Quote 0
                        • O
                          optimusprime @patrick.pesegodinski
                          last edited by

                          @patrick-pesegodinski Did you Apply MSS on WAN interface settings and does it need to be same on both sides of tunnel ?

                          P 1 Reply Last reply Reply Quote 0
                          • P
                            patrick.pesegodinski @optimusprime
                            last edited by

                            @optimusprime I apply in this option:

                            d15f6b0e-dc4f-4612-9973-a628ee43d373-image.png

                            8d1c5b5b-af44-4ef6-aa5f-1b5f3cfd3100-image.png

                            1 Reply Last reply Reply Quote 0
                            • First post
                              Last post
                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.