Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    VPN IPSEC Very Slow

    Scheduled Pinned Locked Moved IPsec
    9 Posts 3 Posters 1.3k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • C
      cunhaigo23
      last edited by

      Good afternoon, how are you?, I'm having a slow VPN (Ipsec) problem, in one branch I'm using Pfsense 2.4.5-RELEASE-p1 and the other Pfsense 2.7.2 with AES 128 BITS SHA257 algorithm on both, could anyone tell me to help ?

      M 1 Reply Last reply Reply Quote 0
      • M
        michmoor LAYER 8 Rebel Alliance @cunhaigo23
        last edited by

        @cunhaigo23
        how do you know its slow?
        what does slow mean? Whats the context? Internet speed at both locations? iperf tests done?

        Firewall: NetGate,Palo Alto-VM,Juniper SRX
        Routing: Juniper, Arista, Cisco
        Switching: Juniper, Arista, Cisco
        Wireless: Unifi, Aruba IAP
        JNCIP,CCNP Enterprise

        C 1 Reply Last reply Reply Quote 0
        • C
          cunhaigo23 @michmoor
          last edited by

          @michmoor In both places we have 300mb/s links and we tested on other links as well and the result is the same 6mb/s. There is no bandwidth control in both places.

          M 1 Reply Last reply Reply Quote 0
          • M
            michmoor LAYER 8 Rebel Alliance @cunhaigo23
            last edited by

            @cunhaigo23
            But how are you testing? iperf or smb or....?
            You havent provided any information that could be used to figure out why speeds are slow.

            Firewall: NetGate,Palo Alto-VM,Juniper SRX
            Routing: Juniper, Arista, Cisco
            Switching: Juniper, Arista, Cisco
            Wireless: Unifi, Aruba IAP
            JNCIP,CCNP Enterprise

            C 1 Reply Last reply Reply Quote 0
            • C
              cunhaigo23 @michmoor
              last edited by

              @michmoor I tested via ftp and smb, both are slow and from different machines, the ipsec interface is not blocking anything, could it be something with the different versions of the two firewalls?

              M 1 Reply Last reply Reply Quote 0
              • M
                michmoor LAYER 8 Rebel Alliance @cunhaigo23
                last edited by

                @cunhaigo23
                SMB is a poor way to test throughput over VPN due to how the protocol works and latency.
                What is the latency between sites?
                What ist he CPU usage during file transfers?
                Are you able to achieve full bandwisth when using a speedtest - not going through a vpn?

                Firewall: NetGate,Palo Alto-VM,Juniper SRX
                Routing: Juniper, Arista, Cisco
                Switching: Juniper, Arista, Cisco
                Wireless: Unifi, Aruba IAP
                JNCIP,CCNP Enterprise

                C 1 Reply Last reply Reply Quote 0
                • C
                  cunhaigo23 @michmoor
                  last edited by

                  @michmoor In terms of the speedtest, we achieved full speed, the latency between sites is low, the CPU does not exceed 10%, could there be something related to different versions of pfsense?

                  1 Reply Last reply Reply Quote 0
                  • N
                    NOCling
                    last edited by

                    How did you set the MSS?
                    Give 1328 try.

                    Netgate 6100 & Netgate 2100

                    C 1 Reply Last reply Reply Quote 0
                    • C
                      cunhaigo23 @NOCling
                      last edited by

                      @NOCling Greetings, thank you very much for the tip, I will test it and report it here, thank you very much

                      1 Reply Last reply Reply Quote 0
                      • First post
                        Last post
                      Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.