Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Upstream very low compared with downstream traffic with OpenVPN Client.

    Scheduled Pinned Locked Moved OpenVPN
    23 Posts 6 Posters 2.0k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • R
      ramses.sevilla @Pippin
      last edited by

      Hi @Pippin

      On client side no problem neither, I have 300Mb/300Mb

      Regards

      1 Reply Last reply Reply Quote 0
      • GertjanG
        Gertjan @JKnott
        last edited by

        @JKnott said in Upstream very low compared with downstream traffic with OpenVPN Client.:

        I have a 75/10 Mb package. If my VPN were connected to someone else with the same configuration, that VPN would be limited to 10 Mb in both directions,

        What about 5 Mb/sec ?

        I imagine something like this :

        Someone from the outside world connects to your 75/10 Mb VPN server.
        This some one executes a speed test, available on the net.
        This connection comes in over the "75Mb/sec" VPN pipe, using the WAN interface.
        And goes out over the same WAN interface pipe, over the 10Mb/sec pipe to the speed test server.
        Then comes back over the 75Mb/sec WAN pipe.
        Goes over the VPN 10Mb/sec pipe to the "some one".

        The 75 and 10 pipe will get used each twice.
        In theory, 10 Mb/sec will be cut in half. (right ?)

        True, (VPN) compression could help here. And VPN traffic control will add some overhead.

        No "help me" PM's please. Use the forum, the community will thank you.
        Edit : and where are the logs ??

        JKnottJ R A 3 Replies Last reply Reply Quote 0
        • JKnottJ
          JKnott @Gertjan
          last edited by

          @Gertjan

          If you are in fact going in and out through the same interface twice, then yes throughput will be cut in half.

          PfSense running on Qotom mini PC
          i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
          UniFi AC-Lite access point

          I haven't lost my mind. It's around here...somewhere...

          1 Reply Last reply Reply Quote 0
          • R
            ramses.sevilla @Gertjan
            last edited by

            Hi @Gertjan

            In that situation is correct but in my case I have two WAN with 250Mb/250Mb. The clients connect to WAN1 an goes to Internet trought the WAN2 or viceversa.

            Regards

            1 Reply Last reply Reply Quote 0
            • PippinP
              Pippin
              last edited by Pippin

              So,

              Client -> OVPNWAN1 -> OVPNWAN2 -> ???

              Better draw a clear diagram...

              I gloomily came to the ironic conclusion that if you take a highly intelligent person and give them the best possible, elite education, then you will most likely wind up with an academic who is completely impervious to reality.
              Halton Arp

              R 1 Reply Last reply Reply Quote 0
              • stephenw10S
                stephenw10 Netgate Administrator
                last edited by stephenw10

                Most tests only test in one direction at a time so whilst that traffic has to go in and out at the VPN server the reply traffic the other way is minimal so I would expect somewhere close to the line rate. But, yeah, any reply traffic there is will reduce the potential test rate.

                Steve

                1 Reply Last reply Reply Quote 0
                • R
                  ramses.sevilla @Pippin
                  last edited by

                  @Pippin this's the diagram:

                  Case 1.- Client -> Internet -> OVPN-WAN1 -> WAN2 -> Internet

                  Case 2.- Client -> Internet -> OVPN-WAN2 -> WAN1 -> Internet

                  Regards

                  1 Reply Last reply Reply Quote 0
                  • P
                    pwood999
                    last edited by

                    Assuming the Client is at a remote location, maybe the client VPN software is limiting the speed ?

                    R 1 Reply Last reply Reply Quote 0
                    • R
                      ramses.sevilla @pwood999
                      last edited by

                      Hi @pwood999

                      I think that no because OpenVPN Client is installed by default and I think that isn't limited in any direction.

                      1 Reply Last reply Reply Quote 0
                      • stephenw10S
                        stephenw10 Netgate Administrator
                        last edited by

                        So to be clear you're seeing the same throughput when connecting via either WAN?

                        Steve

                        R 1 Reply Last reply Reply Quote 0
                        • R
                          ramses.sevilla @stephenw10
                          last edited by

                          Hi @stephenw10

                          I don't understand the question.

                          Regards

                          stephenw10S 1 Reply Last reply Reply Quote 0
                          • P
                            pwood999
                            last edited by

                            If the Server has 250Mb/250Mb. and the Client side has 300Mb/300Mb then the issue must be either server or client performance, unless you have some other limiters configured.

                            R 1 Reply Last reply Reply Quote 0
                            • R
                              ramses.sevilla @pwood999
                              last edited by

                              Hi @pwood999

                              This is clear, but what can I do?. This is the question...

                              Do I need to change any OVPN parameter?

                              No, I haven't configured any limiter on any side.

                              Regards

                              1 Reply Last reply Reply Quote 0
                              • stephenw10S
                                stephenw10 Netgate Administrator @ramses.sevilla
                                last edited by

                                @ramses-sevilla said in Upstream very low compared with downstream traffic with OpenVPN Client.:

                                I don't understand the question.

                                You showed two connection cases, connecting via WAN1 or connecting via WAN2.

                                Do you see the same throughput restriction in both cases?

                                Steve

                                R 1 Reply Last reply Reply Quote 0
                                • P
                                  pwood999
                                  last edited by pwood999

                                  What hardware are your HA PfSense pair running on ?
                                  Are you using physical or virtual machines ?
                                  What CPU & OS does the client PC use ?

                                  Might be worth posting your OpenVPN configs (excluding public IP & secrets).

                                  Also maybe this thread should be moved to OpenVPN forum ?

                                  R 1 Reply Last reply Reply Quote 0
                                  • R
                                    ramses.sevilla @stephenw10
                                    last edited by

                                    Hi @stephenw10

                                    Yes, I see the same.

                                    Regards

                                    1 Reply Last reply Reply Quote 0
                                    • R
                                      ramses.sevilla @pwood999
                                      last edited by

                                      @pwood999 said in Upstream very low compared with downstream traffic with OpenVPN Client.:

                                      What hardware are your HA PfSense pair running on ?
                                      Are you using physical or virtual machines ?
                                      What CPU & OS does the client PC use ?

                                      Might be worth posting your OpenVPN configs (excluding public IP & secrets).

                                      Also maybe this thread should be moved to OpenVPN forum ?

                                      Hi @pwood999

                                      I am using two physical machines Supermicro SuperServer 5018D-FN8T.

                                      The Client is a I5 with UBUNTU 18.04LTS.

                                      Can you tell me where is the text OpenVPN Server config file in pfSense?

                                      Regards and thanks

                                      GertjanG 1 Reply Last reply Reply Quote 0
                                      • GertjanG
                                        Gertjan @ramses.sevilla
                                        last edited by

                                        @ramses-sevilla said in Upstream very low compared with downstream traffic with OpenVPN Client.:

                                        Can you tell me where is the text OpenVPN Server config file in pfSense?

                                        The info you entered on the GUI config is used to create this OpenVPN server config file(s).
                                        So, you know what's in it ;) Bcause you entered that info - or accepted default values.

                                        Look here :

                                        /var/etc/openvpn/
                                        

                                        You'll find serverx.* files where x is the OpenVPN server number, typically 1.

                                        No "help me" PM's please. Use the forum, the community will thank you.
                                        Edit : and where are the logs ??

                                        1 Reply Last reply Reply Quote 0
                                        • First post
                                          Last post
                                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.