Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Slow download speed

    Scheduled Pinned Locked Moved Problems Installing or Upgrading pfSense Software
    25 Posts 3 Posters 1.2k Views 3 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M Offline
      maverick_slo @stephenw10
      last edited by

      @stephenw10

      What can I do? ๐Ÿ™‚

      1 Reply Last reply Reply Quote 0
      • stephenw10S Offline
        stephenw10 Netgate Administrator
        last edited by

        You could try pinging with large packets to determine any MTU restriction in the path. Setting MSS to 1200 should have eliminated that unless it's very restricted.

        In the screenshot of the pcap we can see large packets arriving from the pkg servers but none going the other way.

        Though the fact that pfSense is continually sending duplicate ACKs seems to imply that it's not seeing the incoming packets from the server even though they are reaching the NIC.

        I assume you are not seeing traffic blocked in the firewall log? Do you have custom block rules that might block that without logging?

        Do you have more than one WAN? Is it possible traffic is using both?

        Something else could be dropping traffic on the WAN like traffic shaping or Snort.

        M 1 Reply Last reply Reply Quote 0
        • M Offline
          maverick_slo @stephenw10
          last edited by

          @stephenw10
          No, one wan.

          2 locations, same ISP....

          Happens same on both locations even if I try to use installer for new install so no snort or whatever..

          JeGrJ 1 Reply Last reply Reply Quote 0
          • JeGrJ Offline
            JeGr LAYER 8 Moderator @maverick_slo
            last edited by

            @maverick_slo Are you running WAN IPv4 only or with dualstack (IPv6), too?

            I've seen quite a few installs from us with dual stack where especially v6 was slow as hell. Disabling v6 (setting v6 gateway to none to force it to run via v4) was way faster. As sad as that is...

            Just an idea.

            Don't forget to upvote ๐Ÿ‘ those who kindly offered their time and brainpower to help you!

            If you're interested, I'm available to discuss details of German-speaking paid support (for companies) if needed.

            M 1 Reply Last reply Reply Quote 0
            • M Offline
              maverick_slo @JeGr
              last edited by

              @JeGr nop
              No ipv6 at all..

              Also no firewall rules that would block anything...

              1 Reply Last reply Reply Quote 0
              • stephenw10S Offline
                stephenw10 Netgate Administrator
                last edited by

                Are you able to upload that pcap (or one like it) so we can look at it? That looks so catastrophic it should show something where it first fails.

                https://nc.netgate.com/nextcloud/s/gmrTnLwJyNjNpqa

                M 1 Reply Last reply Reply Quote 0
                • M Offline
                  maverick_slo @stephenw10
                  last edited by

                  @stephenw10
                  Hi.
                  Upliaded to your and mine Nextcloud ๐Ÿ™‚

                  Hope u see something..

                  1 Reply Last reply Reply Quote 0
                  • stephenw10S Offline
                    stephenw10 Netgate Administrator
                    last edited by

                    Hmm, unfortunately that doesn't include the initial part of the connection where it first fails. Are you able to get a pcap including that? If you just run pkg update for example.

                    Was is that running on? The MAC addresses for pfSense and it's gateway are unusual.

                    M 2 Replies Last reply Reply Quote 0
                    • M Offline
                      maverick_slo @stephenw10
                      last edited by

                      @stephenw10
                      Uploaded: telemach_netgate_PKG_UPDATE.pcap

                      But it`s just 9KB...

                      1 Reply Last reply Reply Quote 0
                      • M Offline
                        maverick_slo @stephenw10
                        last edited by

                        @stephenw10 pkg_install_start.pcap uploaded.
                        It replicates behaviour and I started packet capture before trying to install freeradius package...

                        MAC addresses are Hyper-V, my firewall is virtual machine...

                        1 Reply Last reply Reply Quote 0
                        • stephenw10S Offline
                          stephenw10 Netgate Administrator
                          last edited by

                          Hmm, something weird going on there. The packets are arriving out of order at the WAN. You can see in that pkg_install_start pcap where it first fails at packets 24-26. Packets 24 and 25 are reversed.

                          Do you have any hardware off-loading enabled?

                          If there any sort of proxy involved here? Something set in Hyper-V?

                          Can you test a bare metal install from the same location?

                          M 1 Reply Last reply Reply Quote 0
                          • M Offline
                            maverick_slo @stephenw10
                            last edited by

                            @stephenw10
                            Bare metal same issue.
                            No proxy at all

                            2 locations, same ISP

                            1. Has Sonicwall firewall
                            2. Has pfsense firewall

                            So common thing is download from netgate and ISP...

                            M 1 Reply Last reply Reply Quote 0
                            • M Offline
                              maverick_slo @maverick_slo
                              last edited by

                              Im testing with file on my phone...

                              http://pfsense-plus-pkg00.atx.netgate.com/beta/packages/pfSense_plus-master_amd64-core/All/pfSense-kernel-debug-pfSense-23.01.b.20230106.0600.pkg

                              On my isp, slow dl speed on wifi.

                              I have then 2 sims, 2 different isps...

                              On both those isps speed is ok.

                              1 Reply Last reply Reply Quote 0
                              • stephenw10S Offline
                                stephenw10 Netgate Administrator
                                last edited by

                                Oh so you still see this even without pfSense involved at all? It must be a problem in the route then. Like something at your ISP routing packets via multiple routes perhaps.

                                What happens if you route traffic over a VPN to somewhere else so you bypass anything the ISP is doing?

                                1 Reply Last reply Reply Quote 0
                                • First post
                                  Last post
                                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.