IPSec is very slow between two pfsense routers
-
Post your iPerf syntax here so we can understand what you are doing.
Something along the lines ofiperf3 -c 192.168.70.26 -P 50 -t 30
Also post for us the before MSS change and after MSS change results.
-
@keyser
I found something in redmine for MTU suggestions.https://redmine.pfsense.org/issues/14508
-
@michmoor Excuse my ignorance, but I'm not familiar with iperf. Which fields do I need to adjust?
-
@patrick-pesegodinski
do not use iperf on the firewall.
use iperf between your clients (sitting behind your firewall). -
@michmoor 1f121d95-5939-4faa-a741-3386bf11b08d-TESTE.txt
The test with MSS standard.
-
https://packetpushers.net/ipsec-bandwidth-overhead-using-aes/
Best MSS for IPsec tunnel Model 1328, if you use transport Mode and a 1500 WAN line, you can use 1372. -
@NOCling hello friend.
Thanks for helping me. Your information about MSS with 1328 solved my problem.
-
-
@patrick-pesegodinski Did you Apply MSS on WAN interface settings and does it need to be same on both sides of tunnel ?
-