• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

HAproxy slow on WAN jagged throughput

Scheduled Pinned Locked Moved Cache/Proxy
31 Posts 3 Posters 4.5k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • D
    dragoangel @se4n_1
    last edited by Oct 26, 2020, 4:31 PM

    @se4n_1 hi, actually your answer can help other people as it describes that ISP can also cause performance issues :)

    Latest stable pfSense on 2x XG-7100 and 1x Intel Xeon Server, running mutiWAN, he.net IPv6, pfBlockerNG-devel, HAProxy-devel, Syslog-ng, Zabbix-agent, OpenVPN, IPsec site-to-site, DNS-over-TLS...
    Unifi AP-AC-LR with EAP RADIUS, US-24

    1 Reply Last reply Reply Quote 0
    • S
      S_m
      last edited by Oct 26, 2020, 5:51 PM

      I saw the post and redid a test on my side, and the same behaviour, not getting the throughput. I have to test again, but thad the same throtling on multiple ISP with different servers all with HAproxy...

      1 Reply Last reply Reply Quote 0
      • D
        dragoangel
        last edited by Oct 26, 2020, 6:02 PM

        @S_m not sure how you get this really. If I download file bigger than 1gb it easily take full bandwidth in my case.

        Latest stable pfSense on 2x XG-7100 and 1x Intel Xeon Server, running mutiWAN, he.net IPv6, pfBlockerNG-devel, HAProxy-devel, Syslog-ng, Zabbix-agent, OpenVPN, IPsec site-to-site, DNS-over-TLS...
        Unifi AP-AC-LR with EAP RADIUS, US-24

        S 1 Reply Last reply Oct 26, 2020, 6:15 PM Reply Quote 0
        • S
          S_m @dragoangel
          last edited by Oct 26, 2020, 6:15 PM

          @dragoangel I can get full bandwidth between VLANs, and saturate the link on the ISP side, but when I'm out of my ISP things jagged output.

          I can have easy on my box with iPerfs or speedtest.org peaks of 950mbit download.. and upload.. So it's a mess not being able to use HA proxy to deliver high throughput.

          D 1 Reply Last reply Oct 26, 2020, 6:20 PM Reply Quote 0
          • D
            dragoangel @S_m
            last edited by Oct 26, 2020, 6:20 PM

            @S_m Haproxy doesn't change any workflow comparing vlan and ISP, I think it obvious. And obvious where the issue located as problem start only at ISP.

            Latest stable pfSense on 2x XG-7100 and 1x Intel Xeon Server, running mutiWAN, he.net IPv6, pfBlockerNG-devel, HAProxy-devel, Syslog-ng, Zabbix-agent, OpenVPN, IPsec site-to-site, DNS-over-TLS...
            Unifi AP-AC-LR with EAP RADIUS, US-24

            S 1 Reply Last reply Oct 26, 2020, 6:29 PM Reply Quote 0
            • S
              S_m @dragoangel
              last edited by Oct 26, 2020, 6:29 PM

              @dragoangel the main issue is the jagged throughput only happens when traffic goes through HAproxy over internet. But if I put the traffic directly (port forward) goes perfectly fine at maximum speed.

              D 1 Reply Last reply Oct 26, 2020, 6:32 PM Reply Quote 0
              • D
                dragoangel @S_m
                last edited by Oct 26, 2020, 6:32 PM

                @S_m what if you setup haproxy on Linux and nat it over pfsense?

                Latest stable pfSense on 2x XG-7100 and 1x Intel Xeon Server, running mutiWAN, he.net IPv6, pfBlockerNG-devel, HAProxy-devel, Syslog-ng, Zabbix-agent, OpenVPN, IPsec site-to-site, DNS-over-TLS...
                Unifi AP-AC-LR with EAP RADIUS, US-24

                S 1 Reply Last reply Oct 26, 2020, 6:38 PM Reply Quote 0
                • S
                  S_m @dragoangel
                  last edited by Oct 26, 2020, 6:38 PM

                  @dragoangel after the first post and when COVID first started ... I tested another scenarios:
                  ---> NAT nginx: better throughput!
                  ---> HAproxy on Linux Server : Same behavour with other ISP
                  ---> Another pfsense with HAproxy: same issues.

                  D 1 Reply Last reply Oct 26, 2020, 7:26 PM Reply Quote 0
                  • D
                    dragoangel @S_m
                    last edited by Oct 26, 2020, 7:26 PM

                    @S_m if you have same result on multiple os (freebsd/linux) and with multiple ISP then ask haproxy directly on their forum, but this really sound strange

                    Latest stable pfSense on 2x XG-7100 and 1x Intel Xeon Server, running mutiWAN, he.net IPv6, pfBlockerNG-devel, HAProxy-devel, Syslog-ng, Zabbix-agent, OpenVPN, IPsec site-to-site, DNS-over-TLS...
                    Unifi AP-AC-LR with EAP RADIUS, US-24

                    1 Reply Last reply Reply Quote 0
                    • S
                      S_m
                      last edited by Oct 26, 2020, 8:11 PM

                      Yes, I need to test this on another country, on Spain I get this bad results. Trying to diagnose what really happened, The post is because of the problem happened on my pfsense.

                      That's why having someone test this too would be great.

                      D 1 Reply Last reply Oct 26, 2020, 8:21 PM Reply Quote 0
                      • D
                        dragoangel @S_m
                        last edited by Oct 26, 2020, 8:21 PM

                        @S_m if you create post at haproxy community it will be good if you cross link posts to haproxy and from.

                        Latest stable pfSense on 2x XG-7100 and 1x Intel Xeon Server, running mutiWAN, he.net IPv6, pfBlockerNG-devel, HAProxy-devel, Syslog-ng, Zabbix-agent, OpenVPN, IPsec site-to-site, DNS-over-TLS...
                        Unifi AP-AC-LR with EAP RADIUS, US-24

                        1 Reply Last reply Reply Quote 0
                        • D
                          dragoangel
                          last edited by dragoangel Oct 26, 2020, 8:29 PM Oct 26, 2020, 8:24 PM

                          @S_m do you tried http/2? In theory it not help on one big file but still. Also you can try something like loader.io

                          Latest stable pfSense on 2x XG-7100 and 1x Intel Xeon Server, running mutiWAN, he.net IPv6, pfBlockerNG-devel, HAProxy-devel, Syslog-ng, Zabbix-agent, OpenVPN, IPsec site-to-site, DNS-over-TLS...
                          Unifi AP-AC-LR with EAP RADIUS, US-24

                          1 Reply Last reply Reply Quote 0
                          31 out of 31
                          • First post
                            31/31
                            Last post
                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                            This community forum collects and processes your personal information.
                            consent.not_received