Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    tinc and UDP

    Scheduled Pinned Locked Moved pfSense Packages
    3 Posts 2 Posters 701 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • N
      NineEyes
      last edited by

      I have tinc running between my SG-3100 (2.4.5-RELEASE-p1 with tinc 1.0.35_2) and a Fresh Tomato router (2020.5 with tinc 1.1pre17-de7d5a0) over the Internet. The problem: I can't get them to use UDP to transfer data, which is needed to improve throughput.

      With Wireshark, I can see the Tomato router periodically send a UDP packet to port 655 of the SG-3100. With tcpdump on the SG-3100, I can see those packets come in, but I don't see any UDP traffic come from tincd on the SG-3100. The tinc logs don't show anything interesting (to my untrained eyes) on either end even at debug level 5. I don't see any blocking of port 655 in the SG-3100 firewall logs. Neither end is using TCPOnly in their configs.

      Any advice?

      viktor_gV 1 Reply Last reply Reply Quote 0
      • viktor_gV
        viktor_g Netgate @NineEyes
        last edited by

        @nineeyes You need to add a firewall rule that passes tinc

        N 1 Reply Last reply Reply Quote 0
        • N
          NineEyes @viktor_g
          last edited by

          @viktor_g I had that. I left out one key bit of information which I was unaware was relevant at the time: That is, my SG-3100 was running multiWAN and my Tomato router was behind it. I had issues with NAT reflection requirements that I did not sort out completely before giving up on that configuration.

          I moved the Tomato router from behind the SG-3100 and put it directly on it's own WAN connection and then the Tinc UDP flowed fine in both directions.

          How was the bandwidth using iperf3? Not great. At 15mbps the single core of the Tomato router (an Asus RT-AC66U) was maxed out while one of the cores of the SG-3100 never exceeded 16% running tincd.

          1 Reply Last reply Reply Quote 0
          • First post
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.