• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

openvpn performance issue after update to 2.5

Scheduled Pinned Locked Moved OpenVPN
6 Posts 3 Posters 821 Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • D
    denndsd
    last edited by Jun 25, 2021, 6:21 PM

    Hi together,

    today i updated my pfsense to the latest version.
    Also i updated the openvpn package to 2.5
    So now, i have the latest version on it.
    My problem , the performance is sooo slow.
    At home i have a 500 Mbit Cable connection , on my server at the datacenter there is a 1 gbit connection,
    So i am using an virtualized pfsense on a vmware esxi.
    on the esxi is hyper threading active an nested virtualization.
    At home i am using my intel xeon 2620 dedicated server as a hardware firewall.
    The connection is up, but i only get around 50 mbps.
    My settings:

    Encryption: AES-128-CBC
    HASH: SHA1
    Compression: no
    Hardware Crypto: Intel RAND

    buffer size: 512kb ( i also changed but nothing happen)

    Any idea whats wrong ?

    I also tried to change the tun-mtu but this is also not correct.

    The firewall have 4GB RAM , 4 Cores CPU.
    The cpu is alway in idle when traffic is running through.

    Thanks

    Br

    Christian

    1 Reply Last reply Reply Quote 0
    • P
      Panoptic
      last edited by Jun 25, 2021, 10:38 PM

      Have you tried setting your hardware crypto to none so AES-NI can handle it?

      1 Reply Last reply Reply Quote 0
      • D
        denndsd
        last edited by Jun 26, 2021, 8:49 AM

        @panoptic yes I also tried this.
        But no change.

        1 Reply Last reply Reply Quote 0
        • P
          Panoptic
          last edited by Jun 26, 2021, 6:31 PM

          It may have something to do with the Scepter/Meltdown mitigations in the newer bsd kernel. Might be time to upgrade to a newer CPU.

          D 1 Reply Last reply Jun 26, 2021, 6:39 PM Reply Quote 0
          • D
            denndsd @Panoptic
            last edited by Jun 26, 2021, 6:39 PM

            @panoptic but the CPU is only used around 20 %

            K 1 Reply Last reply Jul 7, 2021, 7:47 PM Reply Quote 0
            • K
              knothing @denndsd
              last edited by Jul 7, 2021, 7:47 PM

              @denndsd , have you tried to disable all mitigation settings?
              I had similar problem, which I managed to sort out only with downgrade to 2.4.

              1 Reply Last reply Reply Quote 0
              • First post
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                [[user:consent.lead]]
                [[user:consent.not_received]]