Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Behind pfsense and my download speed is cut in half

    Scheduled Pinned Locked Moved General pfSense Questions
    45 Posts 7 Posters 8.8k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • DerelictD
      Derelict LAYER 8 Netgate
      last edited by

      So the Xfinity technician tested the firewall he brought with him and the speed was half?

      If so there is nothing to talk about here. They need to fix it. There is nothing we can do for you.

      Chattanooga, Tennessee, USA
      A comprehensive network diagram is worth 10,000 words and 15 conference calls.
      DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
      Do Not Chat For Help! NO_WAN_EGRESS(TM)

      H 1 Reply Last reply Reply Quote 1
      • H
        hpspar05 @provels
        last edited by

        @provels if you look back at my submissions here, I have other firewalls that were tested; SG1100, UniFi USG etc, all with the same issue behind the Xfinity cable modem and my Netgear CM1000.

        provelsP 1 Reply Last reply Reply Quote 0
        • provelsP
          provels @hpspar05
          last edited by

          @hpspar05 Then we'll all agree it's a Comcast issue.

          Peder

          MAIN - pfSense+ 24.11-RELEASE - Adlink MXE-5401, i7, 16 GB RAM, 64 GB SSD. 500 GB HDD for SyslogNG
          BACKUP - pfSense+ 23.01-RELEASE - Hyper-V Virtual Machine, Gen 1, 2 v-CPUs, 3 GB RAM, 8GB VHDX (Dynamic)

          1 Reply Last reply Reply Quote 1
          • stephenw10S
            stephenw10 Netgate Administrator
            last edited by stephenw10

            Ok then, yeah, it has to be some upstream issue. And unfortunately it sounds like the sort of issue that Comcast will deny for as long as they can before some high level technician fixes it in 2mins. 🙄

            Steve

            H 1 Reply Last reply Reply Quote 2
            • H
              hpspar05 @Derelict
              last edited by

              @Derelict The tech only brought out a test cable modem, he didn’t have a separate Xfinity firewall if that’s a thing.

              1 Reply Last reply Reply Quote 0
              • DerelictD
                Derelict LAYER 8 Netgate
                last edited by

                Whatever it is it's not pfSense. You'll have to work with Xfinity to figure out what it is.

                Chattanooga, Tennessee, USA
                A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                Do Not Chat For Help! NO_WAN_EGRESS(TM)

                H 1 Reply Last reply Reply Quote 0
                • chpalmerC
                  chpalmer
                  last edited by

                  The Netgear CM1000 is generally a stellar modem. Broadcom based. Nothing wrong with those.

                  Try spoofing the mac address of your laptop on your router WAN page. I have seen various cable ISP's hand out very different IP ranges based on MAC address.

                  Triggering snowflakes one by one..
                  Intel(R) Core(TM) i5-4590T CPU @ 2.00GHz on an M400 WG box.

                  1 Reply Last reply Reply Quote 1
                  • H
                    hpspar05 @stephenw10
                    last edited by

                    @stephenw10 yelp and bingo.) Even you guys are throttling my replies, I can’t reply back until after 120sec Lol 😂

                    DerelictD 1 Reply Last reply Reply Quote 0
                    • DerelictD
                      Derelict LAYER 8 Netgate @hpspar05
                      last edited by

                      @hpspar05 Considering the caustic behavior on this thread it's about to be locked unless some actual information is posted.

                      Chattanooga, Tennessee, USA
                      A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                      DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                      Do Not Chat For Help! NO_WAN_EGRESS(TM)

                      H 1 Reply Last reply Reply Quote 0
                      • H
                        hpspar05 @Derelict
                        last edited by

                        @Derelict Yes I think this is so, what’s happening here isn’t something they will own up to or fix though I believe. Ultimately, Xfinity wants people to rent their equipment.

                        1 Reply Last reply Reply Quote 0
                        • stephenw10S
                          stephenw10 Netgate Administrator
                          last edited by

                          You should certainly try spoofing the MAC address to match your laptop if you have not already.

                          H 2 Replies Last reply Reply Quote 0
                          • H
                            hpspar05 @stephenw10
                            last edited by

                            @stephenw10 That’s above my pay grade and skill set Lol 😂. How do I do that? I’m just a novice still learning.;)

                            1 Reply Last reply Reply Quote 0
                            • DerelictD
                              Derelict LAYER 8 Netgate
                              last edited by

                              https://docs.netgate.com/pfsense/en/latest/book/interfaces/interface-configuration.html#mac-address

                              Chattanooga, Tennessee, USA
                              A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                              DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                              Do Not Chat For Help! NO_WAN_EGRESS(TM)

                              H 1 Reply Last reply Reply Quote 0
                              • H
                                hpspar05 @Derelict
                                last edited by

                                @Derelict ummm the dude that was the issue has ceased and desist his actions, so why this from you now? There are guys here help me with this issue so what’s the problem you’re seeing now?

                                1 Reply Last reply Reply Quote 0
                                • H
                                  hpspar05 @Derelict
                                  last edited by

                                  @Derelict we’re getting ready to go to church now, and thanks for the information Derelict

                                  1 Reply Last reply Reply Quote 0
                                  • H
                                    hpspar05 @stephenw10
                                    last edited by

                                    @stephenw10 Update, guess what? ;) we went to Target and picked up a basic Netgear N600 WiFi Dual Band Router connected it to my Netgear CM1000 modem and we got 98mbps down even with my VPN on and the router is only 100mbps.

                                    Conclusion? Xfinity has somehow targeted or tagged my pfsense, a USG, a USG Pro, firewalls for throttling? I don’t know what to make of this, this cheap Netgear router isn’t being cut of it download speed but my pfsense and other enterprise firewalls tested are. Go figure.

                                    1 Reply Last reply Reply Quote 0
                                    • H
                                      hpspar05
                                      last edited by

                                      You guys aren’t going to believe this, after telling Xfinity that I was going find an investigative reporter to look into this issue, and about an hour later... my download speed is back to normal, 167mbps and 7.7mbps. Coincidence?

                                      1 Reply Last reply Reply Quote 0
                                      • kiokomanK
                                        kiokoman LAYER 8
                                        last edited by

                                        ha ha ... i don't think so ...

                                        ̿' ̿'\̵͇̿̿\з=(◕_◕)=ε/̵͇̿̿/'̿'̿ ̿
                                        Please do not use chat/PM to ask for help
                                        we must focus on silencing this @guest character. we must make up lies and alter the copyrights !
                                        Don't forget to Upvote with the 👍 button for any post you find to be helpful.

                                        1 Reply Last reply Reply Quote 1
                                        • stephenw10S
                                          stephenw10 Netgate Administrator
                                          last edited by

                                          Ha. Classic!

                                          1 Reply Last reply Reply Quote 1
                                          • First post
                                            Last post
                                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.