Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    VPN tunnels massively slows down if high network traffic

    Scheduled Pinned Locked Moved General pfSense Questions
    44 Posts 7 Posters 7.8k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • DerelictD
      Derelict LAYER 8 Netgate
      last edited by

      That delay is abysmal.

      Now add the right axis, Traffic, WAN

      Chattanooga, Tennessee, USA
      A comprehensive network diagram is worth 10,000 words and 15 conference calls.
      DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
      Do Not Chat For Help! NO_WAN_EGRESS(TM)

      1 Reply Last reply Reply Quote 0
      • P
        paoloest
        last edited by

        0_1551863632836_Screenshot 2019-03-06 at 10.13.43.png

        1 Reply Last reply Reply Quote 0
        • DerelictD
          Derelict LAYER 8 Netgate
          last edited by

          OK so there is no traffic reason for the delay.

          At first glance I'd say your ISP/Your ISP circuit is having serious problems.

          Chattanooga, Tennessee, USA
          A comprehensive network diagram is worth 10,000 words and 15 conference calls.
          DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
          Do Not Chat For Help! NO_WAN_EGRESS(TM)

          1 Reply Last reply Reply Quote 0
          • P
            paoloest
            last edited by

            depending on the current situation, that i have massive problems at the moment I would assume that as an option as well ...

            just wanted to make sure that there is no config error

            1 Reply Last reply Reply Quote 0
            • DerelictD
              Derelict LAYER 8 Netgate
              last edited by

              There is nothing in pfSense that can send an echo request out WAN and delay the echo reply 1200ms before it arrives on WAN.

              Chattanooga, Tennessee, USA
              A comprehensive network diagram is worth 10,000 words and 15 conference calls.
              DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
              Do Not Chat For Help! NO_WAN_EGRESS(TM)

              1 Reply Last reply Reply Quote 0
              • P
                paoloest
                last edited by paoloest

                I have found out what the issue is. The cheap f*** internet gateway router detects a sync flood and slows down the interface ...

                So I will get a fritzbox as a Modem instead of this thing.

                as a workaround I have disabled all VPN Clients and only use the wan gw. hopefully it will not get to much on my nerves until this evening

                1 Reply Last reply Reply Quote 0
                • stephenw10S
                  stephenw10 Netgate Administrator
                  last edited by

                  Nice, that will do it!

                  You can't disable that? Or tune it? I assume you mean 'SYN flood' which this is not. Something that is a modem only is a better option though I agree.

                  Steve

                  1 Reply Last reply Reply Quote 0
                  • P
                    paoloest
                    last edited by

                    Auto correct did the synโ€œcโ€œ ;)

                    This isp Router cannot tweak anything ...

                    Unfortunately today there are no good modems (stand alone) are available. So another Router where no router is really needed

                    GrimsonG 1 Reply Last reply Reply Quote 0
                    • GrimsonG
                      Grimson Banned @paoloest
                      last edited by

                      @paoloest said in VPN tunnels massively slows down if high network traffic:

                      Unfortunately today there are no good modems (stand alone) are available. So another Router where no router is really needed

                      Sure there are, for (V)DSL you can use the Draytek Vigor 165 for example. For cable it depends on your provider.

                      1 Reply Last reply Reply Quote 0
                      • P
                        paoloest
                        last edited by

                        @grimson said in VPN tunnels massively slows down if high network traffic:

                        Draytek Vigor 165

                        thanks a lot. have seen this, but it costs more then the fritzbox 7530 - the pros of the fritzbox for me were that the modem (with the same specs) is build in and I can have one more security layer. (and with the fritzbox I can fine tune the parameters)

                        would you choose the modem over the router?

                        GrimsonG 1 Reply Last reply Reply Quote 0
                        • GrimsonG
                          Grimson Banned @paoloest
                          last edited by

                          @paoloest said in VPN tunnels massively slows down if high network traffic:

                          would you choose the modem over the router?

                          When using pfSense, always. Double-NAT just adds useless complexity and the pfSense devs are a lot faster in fixing security issues than the AVM devs.

                          1 Reply Last reply Reply Quote 0
                          • P
                            paoloest
                            last edited by

                            And beyond the pfsense there is a Sophos utm for one subnet and an xg for Another.

                            So maybe no bad idea to leave one layer of complexity ;)

                            1 Reply Last reply Reply Quote 0
                            • stephenw10S
                              stephenw10 Netgate Administrator
                              last edited by

                              You guys actually have VDSL2+? No jealousy here! ๐Ÿ˜‰

                              Otherwise the V130 would likely be cheaper.

                              Steve

                              P GrimsonG 2 Replies Last reply Reply Quote 0
                              • P
                                paoloest @stephenw10
                                last edited by paoloest

                                @stephenw10
                                Sounds like another +1 for the vigor

                                Vdsl2+ - 3 weeks to go

                                1 Reply Last reply Reply Quote 0
                                • GrimsonG
                                  Grimson Banned @stephenw10
                                  last edited by Grimson

                                  @stephenw10 said in VPN tunnels massively slows down if high network traffic:

                                  You guys actually have VDSL2+? No jealousy here! ๐Ÿ˜‰

                                  0_1551882900757_VDSL2.jpg

                                  Not to bad for a little village in the hills. Real fiber would be nicer, but that's not going to happen anytime soon here.

                                  Edit: this is with a current link uptime of 6 weeks.

                                  1 Reply Last reply Reply Quote 1
                                  • stephenw10S
                                    stephenw10 Netgate Administrator
                                    last edited by

                                    Nice! ๐Ÿ˜€

                                    1 Reply Last reply Reply Quote 0
                                    • P
                                      paoloest
                                      last edited by paoloest

                                      Today the vigor will arrive and I am prepared to set it up ;)

                                      One question: if it runs as a modem via pppoe and the connection is initiated by the pfsense. How can you dial in the webinterface of the modem? (The wan Interface has no ip in subnet of modem)

                                      Do you have one vlan (7) as Gateway vlan and another as a Management vlan with static ip in the vigor subnet?

                                      1 Reply Last reply Reply Quote 0
                                      • DerelictD
                                        Derelict LAYER 8 Netgate
                                        last edited by

                                        One method:

                                        https://docs.netgate.com/pfsense/en/latest/interfaces/accessing-modem-from-inside-firewall.html

                                        Chattanooga, Tennessee, USA
                                        A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                                        DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                                        Do Not Chat For Help! NO_WAN_EGRESS(TM)

                                        1 Reply Last reply Reply Quote 2
                                        • First post
                                          Last post
                                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.