Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Behind pfsense and my download speed is cut in half

    General pfSense Questions
    7
    45
    7.5k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • johnpozJ
      johnpoz LAYER 8 Global Moderator
      last edited by johnpoz

      Just a wild ass guess to be honest.. But that for sure could explain why a native client is not throttled, and while something behind a router has different speeds if they are doing something with the odd ttl you would see..

      Simple enough to see for yourself with some sniffing.. Here you can see traffic generated by pfsense with the 64 ttl, and then traffic that went through pfsense has 63

      hopttl.png

      Again this is just spit balling an "idea" that "could" possible explain how an isp could dick with speeds if they wanted too, etc. Or could be an issue on their system that doing something based upon some other unknown details of the traffic??

      That they did the test with their own equipment (router) for sure completely rules out anything pfsense is doing or not doing to cause the issue. Do you have say some wifi router you could use - that sees the same problem?

      edit: What specific "modem" are you using it just a true cable modem, or is it a gateway in "bridged" mode - or is also doing nat? Asking for clarification, because seems like 9 out of 10 times someone says "modem" they really mean gateway, ie modem/router combo box and not just actual modem.. Cable connections are quite often true modems - but many of these isp like handing out gateways now..

      An intelligent man is sometimes forced to be drunk to spend time with his fools
      If you get confused: Listen to the Music Play
      Please don't Chat/PM me for help, unless mod related
      SG-4860 24.11 | Lab VMs 2.7.2, 24.11

      H 1 Reply Last reply Reply Quote 1
      • H
        hpspar05 @stephenw10
        last edited by

        @stephenw10 we’re talking about Xfinity techs here now Lol 😂

        The guy that came out went outside several time to “talk” to another Xfinity guy he knows that has a “switch” at his house that maybe could help him shed some light on what I was experiencing but the guy didn’t answer or something else.

        This is why Xfinity needs real competition in the marketplace. I believe they are doing this mess and leaving their techs out to dry, so to speak, when they’re called out for this particular kind of issue.

        provelsP 1 Reply Last reply Reply Quote 0
        • H
          hpspar05 @johnpoz
          last edited by

          @johnpoz my cable modem is an Xfinity approved Netgear CM1000.

          And I truly believe that Xfinity would love for me to replace all of my own equipment for theirs.;)

          1 Reply Last reply Reply Quote 0
          • provelsP
            provels @hpspar05
            last edited by provels

            @hpspar05 When you direct connect to the modem, what IP address do you get? The WAN address or a private address?
            What is the LAN network you are using?
            And what is the modem/gateway make/model?
            If you have VOIP phone service and wireless without additional access points, it's a gateway not a modem. FWIW, I get 300 down through pfSense and a Netgear CM600 modem on Xfinity.

            EDIT - OK, so a CM1000. Are your interfaces on pfSense all set to auto-negotiate?

            Peder

            MAIN - pfSense+ 24.11-RELEASE - Adlink MXE-5401, i7, 16 GB RAM, 64 GB SSD. 500 GB HDD for SyslogNG
            BACKUP - pfSense+ 23.01-RELEASE - Hyper-V Virtual Machine, Gen 1, 2 v-CPUs, 3 GB RAM, 8GB VHDX (Dynamic)

            H 2 Replies Last reply Reply Quote 0
            • H
              hpspar05 @provels
              last edited by

              @provels I get WAN address when directly connected to the cable modem. I get the rated speed I pay for when directly connected to the cable modem, even on the test modem that was brought out yesterday, I got my rates 150mbps when directly connected to their cable modem.

              Here’s my equipment; Netgear CM1000; pfsense 2.4.4 on Protectli Vault 6 port; and UniFi Switch 8 150.

              1 Reply Last reply Reply Quote 0
              • stephenw10S
                stephenw10 Netgate Administrator
                last edited by

                Ah, there may be some confusion here. The technician who came out just replaced your modem? They didn't test a different router behind your modem? Or any other modem/router combo for that matter?

                Steve

                H 2 Replies Last reply Reply Quote 0
                • H
                  hpspar05 @provels
                  last edited by

                  @provels Yes, speed and duplex are set to default autoselect

                  provelsP 1 Reply Last reply Reply Quote 0
                  • H
                    hpspar05 @stephenw10
                    last edited by

                    @stephenw10 nope, he only test his modem and then we directly connected my laptop to it which speed was fine as usual. But once we added the wall behind the his modem, my speed reduced by half for all firewalls tested behind his and my own. So he didn’t think and I didn’t think to connect another modem behind one another, is that what you’re referring too?

                    1 Reply Last reply Reply Quote 0
                    • provelsP
                      provels @hpspar05
                      last edited by

                      @hpspar05 Sounds like it could be a Protectli problem to me. Maybe try one of the other opensource FW products, like OpenSense, Smoothwall, etc. to see if you get similar results.

                      Peder

                      MAIN - pfSense+ 24.11-RELEASE - Adlink MXE-5401, i7, 16 GB RAM, 64 GB SSD. 500 GB HDD for SyslogNG
                      BACKUP - pfSense+ 23.01-RELEASE - Hyper-V Virtual Machine, Gen 1, 2 v-CPUs, 3 GB RAM, 8GB VHDX (Dynamic)

                      H 1 Reply Last reply Reply Quote 0
                      • H
                        hpspar05 @stephenw10
                        last edited by

                        @stephenw10 And yes we tested different firewalls behind both xfinity and my own modems. And he take his modem with him when he left. I don’t do Xfinity equipment if I don’t have to have it;)

                        1 Reply Last reply Reply Quote 0
                        • DerelictD
                          Derelict LAYER 8 Netgate
                          last edited by

                          So the Xfinity technician tested the firewall he brought with him and the speed was half?

                          If so there is nothing to talk about here. They need to fix it. There is nothing we can do for you.

                          Chattanooga, Tennessee, USA
                          A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                          DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                          Do Not Chat For Help! NO_WAN_EGRESS(TM)

                          H 1 Reply Last reply Reply Quote 1
                          • H
                            hpspar05 @provels
                            last edited by

                            @provels if you look back at my submissions here, I have other firewalls that were tested; SG1100, UniFi USG etc, all with the same issue behind the Xfinity cable modem and my Netgear CM1000.

                            provelsP 1 Reply Last reply Reply Quote 0
                            • provelsP
                              provels @hpspar05
                              last edited by

                              @hpspar05 Then we'll all agree it's a Comcast issue.

                              Peder

                              MAIN - pfSense+ 24.11-RELEASE - Adlink MXE-5401, i7, 16 GB RAM, 64 GB SSD. 500 GB HDD for SyslogNG
                              BACKUP - pfSense+ 23.01-RELEASE - Hyper-V Virtual Machine, Gen 1, 2 v-CPUs, 3 GB RAM, 8GB VHDX (Dynamic)

                              1 Reply Last reply Reply Quote 1
                              • stephenw10S
                                stephenw10 Netgate Administrator
                                last edited by stephenw10

                                Ok then, yeah, it has to be some upstream issue. And unfortunately it sounds like the sort of issue that Comcast will deny for as long as they can before some high level technician fixes it in 2mins. 🙄

                                Steve

                                H 1 Reply Last reply Reply Quote 2
                                • H
                                  hpspar05 @Derelict
                                  last edited by

                                  @Derelict The tech only brought out a test cable modem, he didn’t have a separate Xfinity firewall if that’s a thing.

                                  1 Reply Last reply Reply Quote 0
                                  • DerelictD
                                    Derelict LAYER 8 Netgate
                                    last edited by

                                    Whatever it is it's not pfSense. You'll have to work with Xfinity to figure out what it is.

                                    Chattanooga, Tennessee, USA
                                    A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                                    DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                                    Do Not Chat For Help! NO_WAN_EGRESS(TM)

                                    H 1 Reply Last reply Reply Quote 0
                                    • chpalmerC
                                      chpalmer
                                      last edited by

                                      The Netgear CM1000 is generally a stellar modem. Broadcom based. Nothing wrong with those.

                                      Try spoofing the mac address of your laptop on your router WAN page. I have seen various cable ISP's hand out very different IP ranges based on MAC address.

                                      Triggering snowflakes one by one..
                                      Intel(R) Core(TM) i5-4590T CPU @ 2.00GHz on an M400 WG box.

                                      1 Reply Last reply Reply Quote 1
                                      • H
                                        hpspar05 @stephenw10
                                        last edited by

                                        @stephenw10 yelp and bingo.) Even you guys are throttling my replies, I can’t reply back until after 120sec Lol 😂

                                        DerelictD 1 Reply Last reply Reply Quote 0
                                        • DerelictD
                                          Derelict LAYER 8 Netgate @hpspar05
                                          last edited by

                                          @hpspar05 Considering the caustic behavior on this thread it's about to be locked unless some actual information is posted.

                                          Chattanooga, Tennessee, USA
                                          A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                                          DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                                          Do Not Chat For Help! NO_WAN_EGRESS(TM)

                                          H 1 Reply Last reply Reply Quote 0
                                          • H
                                            hpspar05 @Derelict
                                            last edited by

                                            @Derelict Yes I think this is so, what’s happening here isn’t something they will own up to or fix though I believe. Ultimately, Xfinity wants people to rent their equipment.

                                            1 Reply Last reply Reply Quote 0
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.