Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Terrible Internet Speeds

    Scheduled Pinned Locked Moved General pfSense Questions
    20 Posts 7 Posters 1.9k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • johnpozJ
      johnpoz LAYER 8 Global Moderator
      last edited by

      "Squid, SquidGuard"

      Then your not actually downloading anything, the proxy is..

      An intelligent man is sometimes forced to be drunk to spend time with his fools
      If you get confused: Listen to the Music Play
      Please don't Chat/PM me for help, unless mod related
      SG-4860 24.11 | Lab VMs 2.8, 24.11

      1 Reply Last reply Reply Quote 0
      • T
        tnbp
        last edited by

        Thanks for the input Belt, I have been tracking this, but I can't seem to identify any one device that is using it all.

        Could the squid stuff be what is slowing the connection down so dramatically?

        I am new to this stuff, the guy who built this box has now left, so sorry for my lack of knowledge

        Thanks

        1 Reply Last reply Reply Quote 0
        • B
          belt9
          last edited by

          Try just setting up dummynet and see if it solves the problem.
          For your connection create two pipes, one namede up and the other down.
          Set down for 80,000Kbps and up for 32,000Kbps.
          Under each create one queue weighted 100, set the mask on down to destination and to source on up and select /24 for each.

          Now go to diagnostics > command prompt and run the following command:

          ipfw sched 1 config pipe 1 type fq_codel && ipfw sched 2 config pipe 2 type fq_codel
          

          Now go to your firewall rules and for all of your pass rules go to advanced options and add the queues you just made, save and apply.
          From left to right  select up then down.

          This will solve your problem if one client is hogging bandwidth. Even if that's not your problem it will make your network more better.

          1 Reply Last reply Reply Quote 0
          • ?
            A Former User
            last edited by

            What are you downloading and from where? If it's, say an .iso from a legitimate website, you still won't see that 100mbps, but you'll get very decent speeds. But if you're downloading a movie via torrent then that speed depends on the seeders as much as yourself. You may have 40mbps upload, but others probably may have something much worse. The fastest speeds available to me is 60mbps down and 5mbps up. And I live in a fairly developed area.

            1 Reply Last reply Reply Quote 0
            • T
              tnbp
              last edited by

              not even get a 1MB download.

              Thanks Belt9 I will give that a try. Thank you.

              1 Reply Last reply Reply Quote 0
              • johnpozJ
                johnpoz LAYER 8 Global Moderator
                last edited by

                "not even get a 1MB download. "

                From where from what?  before you were saying it was

                "our actual download speed varies between 0.5 -1 mbp"

                An intelligent man is sometimes forced to be drunk to spend time with his fools
                If you get confused: Listen to the Music Play
                Please don't Chat/PM me for help, unless mod related
                SG-4860 24.11 | Lab VMs 2.8, 24.11

                1 Reply Last reply Reply Quote 0
                • stephenw10S
                  stephenw10 Netgate Administrator
                  last edited by

                  You are testing to speedtest.net from a client behind pfSense and seeing ~100Mbps? Yet a file download on that same client is ~1Mbps?

                  Hard to see how anything on the firewall could cause that. Seems more like something upstream that's optimising speedtest.net.

                  With that significant a slowdown I would usually check Status > Interfaces for errors or collisions on any interface. That would affect Speedtest equally though.

                  Steve

                  1 Reply Last reply Reply Quote 0
                  • johnpozJ
                    johnpoz LAYER 8 Global Moderator
                    last edited by

                    "the guy who built this box has now left, so sorry for my lack of knowledge "

                    So it was like this when the guy built it, or has something changed?

                    An intelligent man is sometimes forced to be drunk to spend time with his fools
                    If you get confused: Listen to the Music Play
                    Please don't Chat/PM me for help, unless mod related
                    SG-4860 24.11 | Lab VMs 2.8, 24.11

                    1 Reply Last reply Reply Quote 0
                    • stephenw10S
                      stephenw10 Netgate Administrator
                      last edited by

                      Yes, very good point!

                      Is the connection new if the box is not?

                      That also points to a speed/duplex mismatch.

                      Steve

                      1 Reply Last reply Reply Quote 0
                      • JKnottJ
                        JKnott
                        last edited by

                        @stephenw10:

                        That also points to a speed/duplex mismatch.

                        How often does that happen these days?  Equipment is normally configured to autonegotiate and fixed speed or half duplex have to be specifically configured.  What does the pfSense dashboard show for the WAN  & LAN bandwidth?  Are there any managed switches that might be misconfigured?  Given that speedtest shows 100 Mb, I doubt anything has wrong speed or duplex.

                        PfSense running on Qotom mini PC
                        i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
                        UniFi AC-Lite access point

                        I haven't lost my mind. It's around here...somewhere...

                        1 Reply Last reply Reply Quote 0
                        • stephenw10S
                          stephenw10 Netgate Administrator
                          last edited by

                          Far more often than you might hope! We regularly see customers hit this sort of issue when their provider supplies them new upstream hardware and it's set to fixed speed/duplex. And the other way around less often.

                          Definitely worth checking.

                          Steve

                          1 Reply Last reply Reply Quote 0
                          • JKnottJ
                            JKnott
                            last edited by

                            I don't think I've ever seen that from an ISP.  On the other hand, I have seen misconfigured switches on a couple of occasions.  Regardless, if he's getting 100 Mb from speedtest, I doubt that's the issue.  Perhaps a bit more info on where he's downloading from might shed some light…  Or perhaps looking at what's on the wire, to see if any problems show themselves.

                            PfSense running on Qotom mini PC
                            i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
                            UniFi AC-Lite access point

                            I haven't lost my mind. It's around here...somewhere...

                            1 Reply Last reply Reply Quote 0
                            • DerelictD
                              Derelict LAYER 8 Netgate
                              last edited by

                              Turn up another inside interface that doesn't use squid/squidguard and test again.

                              Chattanooga, Tennessee, USA
                              A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                              DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                              Do Not Chat For Help! NO_WAN_EGRESS(TM)

                              1 Reply Last reply Reply Quote 0
                              • First post
                                Last post
                              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.