Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    High latency

    Routing and Multi WAN
    2
    10
    2.9k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • S
      semperfi
      last edited by

      Hi everyone
      I just want ask for help regarding my network.
      I have already connected all the company properties using Lease Line VPN from an ISP.
      My problem is when office hours started I found out that all of the site office has a high latency specialy on office hours like ive said.
      Some of the times went to RTO (request time out) and another one is when a high latency occured I cannot remote any site using remote desktop for windows and VNC.
      I attached my network for anyone who want to see my network diagram..

      thanks and hope that anyone could lend their help for me.

      Thank You.
      PFSense_Network_Scheme-2.jpg
      PFSense_Network_Scheme-2.jpg_thumb

      1 Reply Last reply Reply Quote 0
      • P
        podilarius
        last edited by

        Just to help me understand, the pfSense is protecting internet on the WAN side (not in diagram) and the LAN handles internal traffic through the VPNs? Do you have any traffic shaping turned on?

        1 Reply Last reply Reply Quote 0
        • S
          semperfi
          last edited by

          the head office has its own internet.. the 2 site that has the pfsense firewall has also its own internet configured on both on its wan interfaces. These 3 sites with their own internet.. shares internet also through proxies.. to the rest of the sites without soho firewall and pfsense. I also used dansguardian for web filter setup. Yes i have a limiter for upload and download for restriction for some user.

          1 Reply Last reply Reply Quote 0
          • S
            semperfi
            last edited by

            And also the Lan.. yes this were the internal traffic on passes through with vpn connections

            1 Reply Last reply Reply Quote 0
            • P
              podilarius
              last edited by

              My guess is that the limiter is the problem. Since the traffic goes into the LAN and typically this is where the limiter is applied, VPN traffic is sent through the limiter. I would create either a new limiter and/or a new rules that does not have limiter above the main rule for the traffic destined for the VPN.

              1 Reply Last reply Reply Quote 0
              • S
                semperfi
                last edited by

                thanks sir

                sir how can allow to pass VNC pass through the firewall

                tnx

                1 Reply Last reply Reply Quote 0
                • P
                  podilarius
                  last edited by

                  Create an alias and in that list all your networks. Then go into the LAN rules and add a new rule above the rule with the limiter (order matters) that says that if the destination is the networks alias, then pass without the limiter tag. You could also try setting the advanced firewall setting, "Bypass firewall rules for traffic on the same interface".

                  1 Reply Last reply Reply Quote 0
                  • S
                    semperfi
                    last edited by

                    thanks for the reply sir..

                    still I cannot use VNC to remote other sites..

                    how to allow vnc traffic through my PFSense.

                    thanks

                    1 Reply Last reply Reply Quote 0
                    • P
                      podilarius
                      last edited by

                      I would try a basic traceroute and ping to make sure that you can get there. If the bypass is in place, no rules should be consulted, so there should be nothing blocking except perhaps at the remote computer. To test, set a local route on the computer you are using to test with to point a remote subnet to the local VPN router. Then try to connect via VNC. If you are not allowed, then something is broken at the remote side.
                      Have you setup any egress filtering on the LAN? The default rule should allow all traffic from the LAN subnet to any where. If you are doing outbound filtering, then just look up the ports (i think tcp 5900 or 5901) and add an allow rule. Or you can just create a rule for the entire remote subnet to allow the traffic.

                      1 Reply Last reply Reply Quote 0
                      • S
                        semperfi
                        last edited by

                        Thanks a lot sir

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.