• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

High latency

Scheduled Pinned Locked Moved Routing and Multi WAN
10 Posts 2 Posters 2.9k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • S
    semperfi
    last edited by Apr 6, 2013, 2:16 PM

    Hi everyone
    I just want ask for help regarding my network.
    I have already connected all the company properties using Lease Line VPN from an ISP.
    My problem is when office hours started I found out that all of the site office has a high latency specialy on office hours like ive said.
    Some of the times went to RTO (request time out) and another one is when a high latency occured I cannot remote any site using remote desktop for windows and VNC.
    I attached my network for anyone who want to see my network diagram..

    thanks and hope that anyone could lend their help for me.

    Thank You.
    PFSense_Network_Scheme-2.jpg
    PFSense_Network_Scheme-2.jpg_thumb

    1 Reply Last reply Reply Quote 0
    • P
      podilarius
      last edited by Apr 6, 2013, 3:44 PM

      Just to help me understand, the pfSense is protecting internet on the WAN side (not in diagram) and the LAN handles internal traffic through the VPNs? Do you have any traffic shaping turned on?

      1 Reply Last reply Reply Quote 0
      • S
        semperfi
        last edited by Apr 7, 2013, 2:06 PM

        the head office has its own internet.. the 2 site that has the pfsense firewall has also its own internet configured on both on its wan interfaces. These 3 sites with their own internet.. shares internet also through proxies.. to the rest of the sites without soho firewall and pfsense. I also used dansguardian for web filter setup. Yes i have a limiter for upload and download for restriction for some user.

        1 Reply Last reply Reply Quote 0
        • S
          semperfi
          last edited by Apr 7, 2013, 2:10 PM

          And also the Lan.. yes this were the internal traffic on passes through with vpn connections

          1 Reply Last reply Reply Quote 0
          • P
            podilarius
            last edited by Apr 8, 2013, 4:12 AM

            My guess is that the limiter is the problem. Since the traffic goes into the LAN and typically this is where the limiter is applied, VPN traffic is sent through the limiter. I would create either a new limiter and/or a new rules that does not have limiter above the main rule for the traffic destined for the VPN.

            1 Reply Last reply Reply Quote 0
            • S
              semperfi
              last edited by Apr 8, 2013, 7:41 AM

              thanks sir

              sir how can allow to pass VNC pass through the firewall

              tnx

              1 Reply Last reply Reply Quote 0
              • P
                podilarius
                last edited by Apr 8, 2013, 9:25 AM

                Create an alias and in that list all your networks. Then go into the LAN rules and add a new rule above the rule with the limiter (order matters) that says that if the destination is the networks alias, then pass without the limiter tag. You could also try setting the advanced firewall setting, "Bypass firewall rules for traffic on the same interface".

                1 Reply Last reply Reply Quote 0
                • S
                  semperfi
                  last edited by Apr 9, 2013, 8:52 AM

                  thanks for the reply sir..

                  still I cannot use VNC to remote other sites..

                  how to allow vnc traffic through my PFSense.

                  thanks

                  1 Reply Last reply Reply Quote 0
                  • P
                    podilarius
                    last edited by Apr 9, 2013, 9:50 AM Apr 9, 2013, 9:25 AM

                    I would try a basic traceroute and ping to make sure that you can get there. If the bypass is in place, no rules should be consulted, so there should be nothing blocking except perhaps at the remote computer. To test, set a local route on the computer you are using to test with to point a remote subnet to the local VPN router. Then try to connect via VNC. If you are not allowed, then something is broken at the remote side.
                    Have you setup any egress filtering on the LAN? The default rule should allow all traffic from the LAN subnet to any where. If you are doing outbound filtering, then just look up the ports (i think tcp 5900 or 5901) and add an allow rule. Or you can just create a rule for the entire remote subnet to allow the traffic.

                    1 Reply Last reply Reply Quote 0
                    • S
                      semperfi
                      last edited by Apr 10, 2013, 6:22 AM

                      Thanks a lot sir

                      1 Reply Last reply Reply Quote 0
                      5 out of 10
                      • First post
                        5/10
                        Last post
                      Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                        This community forum collects and processes your personal information.
                        consent.not_received