Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Poor IPSec performance

    Scheduled Pinned Locked Moved IPsec
    27 Posts 9 Posters 15.9k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • E
      Eugene
      last edited by

      Hi Olejak,
      have you resolved the problem?
      Just interesting…
      Actually it is normal for large packets:
      13:00:47.407446 IP 192.168.42.2 > 192.168.42.1: ESP(spi=0x01e083a4,seq=0x3), length 1480
      13:00:47.407450 IP 192.168.42.2 > 192.168.42.1: esp

      I am just wondering whether you receive the same two packets on the other end? I.e. if it is a trace from FW1 do you see the same packets on FW2?

      http://ru.doc.pfsense.org

      1 Reply Last reply Reply Quote 0
      • J
        jftuga
        last edited by

        Try placing a switch between the 2 pfSense servers.  I ran into issues using crossover cables that were cleared up when I used a gig switch instead.

        -John

        1 Reply Last reply Reply Quote 0
        • valnarV
          valnar
          last edited by

          Set the MTU of your adapters down to 1400 and try again.  Large packets + IPSEC + no fragmentation is a common problem.

          For Windows, you can use this: http://www.dslreports.com/drtcp

          1 Reply Last reply Reply Quote 0
          • E
            Eugene
            last edited by

            @valnar:

            For Windows, you can use this: http://www.dslreports.com/drtcp

            Sounds very interesting. Could you explain in more details? -)

            http://ru.doc.pfsense.org

            1 Reply Last reply Reply Quote 0
            • F
              fastcon68
              last edited by

              Can you please give me a little me details.  I have setup a similiar configuration.  I had a dual 866 with 1 gb of ram  connected over 100 mb connected to compac dl 380 with 100 nics.  no speed issues.  Teested with serveral different issues.
              RC

              1 Reply Last reply Reply Quote 0
              • valnarV
                valnar
                last edited by

                Just google MTU, fragmentation, IPSEC and VPN.

                1 Reply Last reply Reply Quote 0
                • I
                  infratek
                  last edited by

                  Hello Olejack,

                  Did you finally solve your issue ?
                  I'd be very interested as I have the same right now.
                  I've tried to lower MTU on the WAN interface configuration but it's not taken into account even after a reboot.
                  A ifconfig shows an MTU of 1500 even though I entered 1300.
                  I can't find any topic where someone succeeded in modifying the IPSEC MTU.
                  Im' considering to replace ipsec with openvpn maybe.

                  About commercial support, I've asked once for tinydns support and never had any reply …

                  Thanks for your help.

                  1 Reply Last reply Reply Quote 0
                  • First post
                    Last post
                  Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.