Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Download at full speed then got packet loss

    Scheduled Pinned Locked Moved General pfSense Questions
    23 Posts 4 Posters 2.3k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • L
      Lip
      last edited by

      Yes, the limiters make a difference. Bufferbloat goes from F to A.

      The problem remains the same. As soon as I download something and use the line, the ping goes up.

      Download.PNG
      Download2.PNG
      Upload.png
      Upload2.png
      Floating Rule.png

      1 Reply Last reply Reply Quote 0
      • stephenw10S
        stephenw10 Netgate Administrator
        last edited by

        Ok those rules and queues look correct.

        Do you actually see a reduction in available bandwidth when they are applied?

        The key is to have them set slightly below the available speed to that all the queuing is done in pfSense where it can control what is passed and when. You might try setting the values lower to be sure.

        Steve

        L 1 Reply Last reply Reply Quote 0
        • L
          Lip @stephenw10
          last edited by

          @stephenw10

          The Vigor outputs the following values, in my thread above you can see my limits. I would say the limiter works?
          9821d84b-1316-445d-b452-59c62022e76c-image.png

          169aebb9-5e37-451d-9115-98c075cfc0c9-image.png

          But look at these spikes on cmd:
          cfa4e730-bba2-4830-aeb9-96f33106c7a7-image.png

          And this is what my ping looks like when there is only little traffic on the line:

          8b749c47-8bf5-4c9c-9518-957181110364-image.png

          1 Reply Last reply Reply Quote 0
          • RicoR
            Rico LAYER 8 Rebel Alliance
            last edited by

            Bad network card / drivers like Realtek?

            -Rico

            L 1 Reply Last reply Reply Quote 0
            • L
              Lip @Rico
              last edited by Lip

              @rico

              Hi Rico,

              unfortunately you are right. However, I followed the following recommendation regarding the drivers.

              https://forums.serverbuilds.net/t/guide-resolve-realtek-nic-stability-issues-on-freebsd-pfsense-2-4-4-2-4-5-2-5-0-opnsense-use-2-5gb-realtek/3555

              My hardware is the following:
              ZBOX PRO CI329 nano
              https://www.zotac.com/product/mini_pcs/zbox-pro-ci329-nano

              1 Reply Last reply Reply Quote 0
              • RicoR
                Rico LAYER 8 Rebel Alliance
                last edited by

                When it comes to PPPoE, the problems get even worse with Realtek.
                Can you put your WAN in DHCP or Static mode (run double NAT) for testing?

                -Rico

                L 1 Reply Last reply Reply Quote 0
                • L
                  Lip @Rico
                  last edited by

                  @rico
                  Unfortunately, I can't change that. It would be extremely difficult. Is there another option or do I have to buy new hardware?

                  stephenw10S 1 Reply Last reply Reply Quote 0
                  • stephenw10S
                    stephenw10 Netgate Administrator @Lip
                    last edited by

                    What are you pinging in that example?
                    Do you see the same variation to all external IPs?

                    Steve

                    L 1 Reply Last reply Reply Quote 0
                    • RicoR
                      Rico LAYER 8 Rebel Alliance
                      last edited by

                      For my opinion you've bought the wrong device to run pfSense. That ZBOX is ~250 bucks as barebone with 2 Realtek NICs...makes my heart bleeding. 🤕
                      300/50(40) Mbps looks like Telekom Germany, refund that box if possible (14 day window) and get some serious pfSense gear. 😁

                      -Rico

                      L 1 Reply Last reply Reply Quote 0
                      • L
                        Lip @stephenw10
                        last edited by

                        @stephenw10
                        I ping on www.google.de.
                        It doesn't matter what I ping.

                        1 Reply Last reply Reply Quote 0
                        • L
                          Lip @Rico
                          last edited by

                          @rico

                          Yes it is a telecom line.
                          It is really difficult to get good hardware for the PFsense in Germany that is energy efficient.

                          What kind of hardware would you suggest?

                          50a0ba24-9fb6-408a-ba62-08935f2a19da-image.png

                          1 Reply Last reply Reply Quote 0
                          • stephenw10S
                            stephenw10 Netgate Administrator
                            last edited by stephenw10

                            Mmm, the Celeron N4100 is not that fast. It's possible you're hitting something there though you are seeing the full bandwidth. I would expect it to pass 300Mbops without issues though. Maybe it's stuck at the lowest speed.

                            Try running at the CLI top -aSH whilst testing. See if one core at loaded 100%.

                            Steve

                            L 1 Reply Last reply Reply Quote 0
                            • L
                              Lip @stephenw10
                              last edited by

                              @stephenw10

                              83ccdc34-4eec-4d45-bebc-11b78db5739b-image.png

                              Here is a screenshot, is the CPU the problem?

                              stephenw10S 1 Reply Last reply Reply Quote 0
                              • stephenw10S
                                stephenw10 Netgate Administrator @Lip
                                last edited by

                                Nope. All 4 cores are at least 73% idle. That's only 224Mbps though.

                                I'm still not sure you're actually limiting that traffic though.

                                What does the speed test result show when you disable the Limiters? vs with the Limiters?

                                Steve

                                L 1 Reply Last reply Reply Quote 0
                                • L
                                  Lip @stephenw10
                                  last edited by

                                  @stephenw10

                                  Active Limiter

                                  8ac82585-b111-407a-a884-b104a1b22477-image.png

                                  inactive Limiter with States Reset

                                  825687aa-ba6c-48a5-adbe-e15f6feff23a-image.png

                                  stephenw10S 1 Reply Last reply Reply Quote 0
                                  • stephenw10S
                                    stephenw10 Netgate Administrator @Lip
                                    last edited by

                                    Hmm, well that looks OK. Maybe more than FQ_Codel can deal with then.

                                    I don't actually see any packet loss there though, are you still seeing that?

                                    L 1 Reply Last reply Reply Quote 0
                                    • L
                                      Lip @stephenw10
                                      last edited by

                                      @stephenw10

                                      There are always packet losses at full speed downloads. Worse is that the ping rises from 5ms to 50. Then you get problems with Voip

                                      stephenw10S 1 Reply Last reply Reply Quote 0
                                      • stephenw10S
                                        stephenw10 Netgate Administrator @Lip
                                        last edited by

                                        Mmm, the latency is unavoidable to a certain extent though I would not expect packet loss.

                                        You can try setting a lower limit for all other traffic and passing VoIP traffic outside the Limiters to reserve bandwidth for it.

                                        Steve

                                        1 Reply Last reply Reply Quote 0
                                        • AndyRHA
                                          AndyRH
                                          last edited by

                                          @stephenw10 said in Download at full speed then got packet loss:

                                          Celeron N4100

                                          More for my own education than anything, why is the general theme that the HW pfSense is running on is the problem and not the ISP with what looks to be a full link?

                                          While Realtek NICs are not the best, the speed is only 25% of what the NIC should be able to do, so it is not stressed. I would not expect a unstressed NIC causing a problem.

                                          I run on an i3 540 with 4 port Intel 1Gb NIC and even with a speed test running @ 980Mbps and file copies crossing the other NICs I see no change in pings and a CPU getting close to 30%. The CPU in the problem system is generations newer and should be faster per cycle than mine.

                                          o||||o
                                          7100-1u

                                          L stephenw10S 2 Replies Last reply Reply Quote 0
                                          • L
                                            Lip @AndyRH
                                            last edited by

                                            @andyrh
                                            Unfortunately I can not say what the problem is. I only know that if there is no full load traffic on the line, there is no packet loss. I also think that my hardware should be sufficient.

                                            1 Reply Last reply Reply Quote 0
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.