Slow internet speed



  • I have pfsense with E2Guardian and Firewall whose functions are to filter network connection.  I also have Traffic Shaper configured on firewall per group/alias.

    My users complaints that the internet connection is really slow specially on their gmail connection.

    On firewall, I disallowed DNS outside thisfirewall.  DNS is only thru thisfirewall.

    Any thoughts why the connection is slow ?

    PS:  I have also Snort installed on LAN interface whose purpose is to block proxy, vpn, virus, trojan connections.

    UPDATE: I have experienced it myself that the connection is very slow that it timed out on its connection.



  • @ravegen:

    I have pfsense with E2Guardian and Firewall whose functions are to filter network connection.  I also have Traffic Shaper configured on firewall per group/alias.

    My users complaints that the internet connection is really slow specially on their gmail connection.

    On firewall, I disallowed DNS outside thisfirewall.  DNS is only thru thisfirewall.

    Any thoughts why the connection is slow ?

    PS:  I have also Snort installed on LAN interface whose purpose is to block proxy, vpn, virus, trojan connections.

    UPDATE: I have experienced it myself that the connection is very slow that it timed out on its connection.

    Woah, woah, woah. In that type of configuration it could be more than one thing causing the slowness. Start with Snort, depending on the rule sets you have enabled. It will go crazy with the blocking. Then check the traffic shaper, even remove it temporarily.



  • alright i check into it.  but is there a possibility without shaper and snort, could the proxy be causing slow traffic due to number of users?



  • @ravegen:

    alright i check into it.  but is there a possibility without shaper and snort, could the proxy be causing slow traffic due to number of users?

    If you do not adjust it's config to the amount of users you have, then, yes.

    And please, read the package fields description before asking "what options? where? how? why?".



  • @ravegen:

    alright i check into it.  but is there a possibility without shaper and snort, could the proxy be causing slow traffic due to number of users?

    Make sure you adjust HTTP workers, and as Marcello explained. Read through the docs, and the hints within the GUI instead of spamming the forums.



  • oh i have had adjusted my http worker and read the doc and wiki.  its just i am accustomed to making new thread for different issues like in the other forum i also post.



  • You still didn't got the point.

    There is no problem on creating one post for each question. The point is that it seems that you don't try the config or read the options instructions before asking how.



  • actually i do.  like for example, normal group type and deny by ip.

    if im going to read deny by ip, its only deny by ip but does it include normal url filtering? it doesnt say but your option is to try while if it says deny by ip + normal filtering that would be faster and easier to decide and chose.

    another thing, if i select the icap amd av options, would that enable antivirus and where would i see that.  unlike squid, there is tickbox to enable so that would be more meaningful  but  i guess i can complain since  i am mere user.

    but i think you dont get it, if your description would be more descriptive and informative there not much to ask.

    but i ask since this is pfsense forum and i have no knowledge aside from the docs. but still if there is a book, there would still be questions.