Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    WAN Upgrade from 10mb to 20mb but no change from behind firewall

    Scheduled Pinned Locked Moved Hardware
    20 Posts 6 Posters 4.8k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • stephenw10S
      stephenw10 Netgate Administrator
      last edited by

      I think perhaps thinkbroadband or my own ISP had limited the connection because my actual connection is DSL synced at 22Mbps. I can usually get close to 20Mbps real speed.
      Today I retried it and:

      
      [2.0-RC3][root@pfsense.fire.box]/root(2): fetch -o /dev/null http://download.thinkbroadband.com/50MB.zip
      /dev/null                                     100% of   50 MB 1961 kBps 00m00s
      
      

      So, close to 16Mbps. Still not what I know is possible but it's busy time of day. If I'm doing any serious testing I wait until after midnight when I know I'm getting less contention and it doesn't count towards my bandwidth limit.  ;)

      One thing that might be causing you trouble is that ISPs often have a cap on your bandwidth somewhere in their network. It's entirely possible that they increased your line speed but didn't reset the bandwidth cap.

      Steve

      1 Reply Last reply Reply Quote 0
      • A
        atamido
        last edited by

        @jpmtg:

        P.S. Thanks for the heads up of FreeBSD not being from linux. It was based off of Unix then?

        It's worth reading the intro paragraphs here:
        http://en.wikipedia.org/wiki/Berkeley_Software_Distribution

        And if you scroll down there's an image on the right that shows the hierarchy of where the different *nix systems came from.

        1 Reply Last reply Reply Quote 0
        • J
          jpmtg
          last edited by

          @stephenw10:

          I think perhaps thinkbroadband or my own ISP had limited the connection because my actual connection is DSL synced at 22Mbps. I can usually get close to 20Mbps real speed.
          Today I retried it and:

          
          [2.0-RC3][root@pfsense.fire.box]/root(2): fetch -o /dev/null http://download.thinkbroadband.com/50MB.zip
          /dev/null                                     100% of   50 MB 1961 kBps 00m00s
          
          

          So, close to 16Mbps. Still not what I know is possible but it's busy time of day. If I'm doing any serious testing I wait until after midnight when I know I'm getting less contention and it doesn't count towards my bandwidth limit.  ;)

          One thing that might be causing you trouble is that ISPs often have a cap on your bandwidth somewhere in their network. It's entirely possible that they increased your line speed but didn't reset the bandwidth cap.

          Steve

          It was around 1am when I did the test and I didn't see anything else going on. The ISP engineer did a test from their laptop directly connected to WAN and got 22Mbps. From behind the firewall it was 7Mbps. I just noticed that the upload test they did from their equipment showed an increase over what we had previously. It is showing 17Mbps and prior we would have around 8Mbps. So this at least lets me know that only download is being throttled?

          1 Reply Last reply Reply Quote 0
          • stephenw10S
            stephenw10 Netgate Administrator
            last edited by

            Hmm, OK.
            So you have cable WAN or some connection that provides ethernet to your pfSense WAN?
            What does your pfSense box say about the status of your interfaces (GUI > Status > Interfaces), are they all 100Mbps full duplex (or faster)?

            What is the state of your pfSense box? Is it a fresh install? Any packages? Anything else?  ::)

            Steve

            1 Reply Last reply Reply Quote 0
            • J
              jpmtg
              last edited by

              @stephenw10:

              Hmm, OK.
              So you have cable WAN or some connection that provides ethernet to your pfSense WAN?
              What does your pfSense box say about the status of your interfaces (GUI > Status > Interfaces), are they all 100Mbps full duplex (or faster)?

              What is the state of your pfSense box? Is it a fresh install? Any packages? Anything else?  ::)

              Steve

              AT&T MetroE 20Mbps fiber

              WAN and LAN Interfaces:
              1000baseT <full-duplex>Packages:
              iperf
              Lightsquid
              nmap
              squid
              squidGuard

              Fresh install 2.0-RELEASE (i386)
              built on Tue Sep 13 17:00:00 EDT 2011</full-duplex>

              1 Reply Last reply Reply Quote 0
              • J
                jpmtg
                last edited by

                Here are the results using the ISP's test site.

                From the tech's laptop plugged directly into the WAN:

                and here is my test from behind router:

                1 Reply Last reply Reply Quote 0
                • stephenw10S
                  stephenw10 Netgate Administrator
                  last edited by

                  It's hard to say quite what is being measured there. What is the difference between 'download speed' and 'download capacity'?

                  You have quite a few things running on pfSense that could potentially be causing delays; squid and squidguard.

                  Can you hook up a machine directly to the AT&T connection and test from there?

                  Can you boot your pfSense machine from the LiveCD to test without any packages?

                  Steve

                  1 Reply Last reply Reply Quote 0
                  • J
                    jpmtg
                    last edited by

                    @stephenw10:

                    It's hard to say quite what is being measured there. What is the difference between 'download speed' and 'download capacity'?

                    You have quite a few things running on pfSense that could potentially be causing delays; squid and squidguard.

                    Can you hook up a machine directly to the AT&T connection and test from there?

                    Can you boot your pfSense machine from the LiveCD to test without any packages?

                    Steve

                    I had previously disabled squid and tested again with no change. I will work on testing via live cd next time I am on site.

                    1 Reply Last reply Reply Quote 0
                    • P
                      podilarius
                      last edited by

                      Don't just disable them, uninstall them and reboot. You want to make sure that it is package causing the issue and not something deeper. Check your floating rules to make sure shaper has not rules. Remove shaping if there is some there.

                      Even better, backup your config. Re-install pfsense and give it enough just to start passing traffic, then test speed.

                      There might be NIC driver issues, what type of NICs are they again?

                      1 Reply Last reply Reply Quote 0
                      • C
                        cmb
                        last edited by

                        @jpmtg:

                        I will work on testing via live cd next time I am on site.

                        That would be a good plan and without wrecking your existing install, get the most basic config possible to get online and see how that's diff.

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.