Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Slow download speed

    Scheduled Pinned Locked Moved Problems Installing or Upgrading pfSense Software
    25 Posts 3 Posters 1.2k Views 3 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • stephenw10S Offline
      stephenw10 Netgate Administrator
      last edited by

      You could try pinging with large packets to determine any MTU restriction in the path. Setting MSS to 1200 should have eliminated that unless it's very restricted.

      In the screenshot of the pcap we can see large packets arriving from the pkg servers but none going the other way.

      Though the fact that pfSense is continually sending duplicate ACKs seems to imply that it's not seeing the incoming packets from the server even though they are reaching the NIC.

      I assume you are not seeing traffic blocked in the firewall log? Do you have custom block rules that might block that without logging?

      Do you have more than one WAN? Is it possible traffic is using both?

      Something else could be dropping traffic on the WAN like traffic shaping or Snort.

      M 1 Reply Last reply Reply Quote 0
      • M Offline
        maverick_slo @stephenw10
        last edited by

        @stephenw10
        No, one wan.

        2 locations, same ISP....

        Happens same on both locations even if I try to use installer for new install so no snort or whatever..

        JeGrJ 1 Reply Last reply Reply Quote 0
        • JeGrJ Offline
          JeGr LAYER 8 Moderator @maverick_slo
          last edited by

          @maverick_slo Are you running WAN IPv4 only or with dualstack (IPv6), too?

          I've seen quite a few installs from us with dual stack where especially v6 was slow as hell. Disabling v6 (setting v6 gateway to none to force it to run via v4) was way faster. As sad as that is...

          Just an idea.

          Don't forget to upvote ๐Ÿ‘ those who kindly offered their time and brainpower to help you!

          If you're interested, I'm available to discuss details of German-speaking paid support (for companies) if needed.

          M 1 Reply Last reply Reply Quote 0
          • M Offline
            maverick_slo @JeGr
            last edited by

            @JeGr nop
            No ipv6 at all..

            Also no firewall rules that would block anything...

            1 Reply Last reply Reply Quote 0
            • stephenw10S Offline
              stephenw10 Netgate Administrator
              last edited by

              Are you able to upload that pcap (or one like it) so we can look at it? That looks so catastrophic it should show something where it first fails.

              https://nc.netgate.com/nextcloud/s/gmrTnLwJyNjNpqa

              M 1 Reply Last reply Reply Quote 0
              • M Offline
                maverick_slo @stephenw10
                last edited by

                @stephenw10
                Hi.
                Upliaded to your and mine Nextcloud ๐Ÿ™‚

                Hope u see something..

                1 Reply Last reply Reply Quote 0
                • stephenw10S Offline
                  stephenw10 Netgate Administrator
                  last edited by

                  Hmm, unfortunately that doesn't include the initial part of the connection where it first fails. Are you able to get a pcap including that? If you just run pkg update for example.

                  Was is that running on? The MAC addresses for pfSense and it's gateway are unusual.

                  M 2 Replies Last reply Reply Quote 0
                  • M Offline
                    maverick_slo @stephenw10
                    last edited by

                    @stephenw10
                    Uploaded: telemach_netgate_PKG_UPDATE.pcap

                    But it`s just 9KB...

                    1 Reply Last reply Reply Quote 0
                    • M Offline
                      maverick_slo @stephenw10
                      last edited by

                      @stephenw10 pkg_install_start.pcap uploaded.
                      It replicates behaviour and I started packet capture before trying to install freeradius package...

                      MAC addresses are Hyper-V, my firewall is virtual machine...

                      1 Reply Last reply Reply Quote 0
                      • stephenw10S Offline
                        stephenw10 Netgate Administrator
                        last edited by

                        Hmm, something weird going on there. The packets are arriving out of order at the WAN. You can see in that pkg_install_start pcap where it first fails at packets 24-26. Packets 24 and 25 are reversed.

                        Do you have any hardware off-loading enabled?

                        If there any sort of proxy involved here? Something set in Hyper-V?

                        Can you test a bare metal install from the same location?

                        M 1 Reply Last reply Reply Quote 0
                        • M Offline
                          maverick_slo @stephenw10
                          last edited by

                          @stephenw10
                          Bare metal same issue.
                          No proxy at all

                          2 locations, same ISP

                          1. Has Sonicwall firewall
                          2. Has pfsense firewall

                          So common thing is download from netgate and ISP...

                          M 1 Reply Last reply Reply Quote 0
                          • M Offline
                            maverick_slo @maverick_slo
                            last edited by

                            Im testing with file on my phone...

                            http://pfsense-plus-pkg00.atx.netgate.com/beta/packages/pfSense_plus-master_amd64-core/All/pfSense-kernel-debug-pfSense-23.01.b.20230106.0600.pkg

                            On my isp, slow dl speed on wifi.

                            I have then 2 sims, 2 different isps...

                            On both those isps speed is ok.

                            1 Reply Last reply Reply Quote 0
                            • stephenw10S Offline
                              stephenw10 Netgate Administrator
                              last edited by

                              Oh so you still see this even without pfSense involved at all? It must be a problem in the route then. Like something at your ISP routing packets via multiple routes perhaps.

                              What happens if you route traffic over a VPN to somewhere else so you bypass anything the ISP is doing?

                              1 Reply Last reply Reply Quote 0
                              • First post
                                Last post
                              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.