<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Gigabit Throughput]]></title><description><![CDATA[<p dir="auto">Howdy! I'm on a gigabit cable connection and can't get much more then 230 meg though my pfSense firewall. I've checked all the interfaces are at 1000baseT full duplex with no errors. I'm only running one VPN that isn't used for internet traffic. Hardware is below and doesn't seem to be taxed in anyway:</p>
<p dir="auto">Intel(R) Core(TM)2 Duo CPU E8400 @ 3.00GHz<br />
Current: 1998 MHz, Max: 3000 MHz<br />
2 CPUs: 1 package(s) x 2 core(s)<br />
AES-NI CPU Crypto: No<br />
4 GB of RAM</p>
<p dir="auto">Running 2.4.4-RELEASE-p1 (amd64)</p>
<p dir="auto">I see a bunch of advise to disable snort, traffic shaping, and other services, but I'm just running simple NAT. Where should I look next?</p>
]]></description><link>https://forum.netgate.com/topic/138586/gigabit-throughput</link><generator>RSS for Node</generator><lastBuildDate>Tue, 15 Sep 2026 15:00:05 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/138586.rss" rel="self" type="application/rss+xml"/><pubDate>Mon, 10 Dec 2018 20:40:18 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Gigabit Throughput on Tue, 18 Dec 2018 00:45:16 GMT]]></title><description><![CDATA[<p dir="auto">This is my test :</p>
<p dir="auto"><img src="/assets/uploads/files/1545093182755-3gbit-iperf-resized.png" alt="0_1545093184825_3Gbit iPerf.PNG" class=" img-fluid img-markdown" /></p>
<p dir="auto">I run pfSense on Cisco UCS C210 M2 with 2x X5650 CPU and BroadCom QLogic dual port 10G NIC... Maximum load I registered was 11%...<br />
I am pretty sure this result is caused by a speed limitations between me and server instead of my pfSense box... After a few day I will have second 10G line from separate ISP and then I can test again... This machine was released in 2010 so almost 9 years old but works pretty well and I am happy with it ;)</p>
]]></description><link>https://forum.netgate.com/post/811852</link><guid isPermaLink="true">https://forum.netgate.com/post/811852</guid><dc:creator><![CDATA[Kartoff]]></dc:creator><pubDate>Tue, 18 Dec 2018 00:45:16 GMT</pubDate></item><item><title><![CDATA[Reply to Gigabit Throughput on Mon, 17 Dec 2018 22:12:39 GMT]]></title><description><![CDATA[<p dir="auto">It's probably fine.</p>
<p dir="auto">Before you test the firewall throughput put both the iperf3 server and client machines on the same subnet and test between them directly. Make sure you can see gigabit line rate in both directions.</p>
<p dir="auto">Then move the server machine into the WAN subet and test against it with the client on the LAN.</p>
<p dir="auto">If you don't see &gt;900Mbps both ways then look for errors on the interfaces. Try running <code>top -aSH</code> on the firewall during the test to see the cpu core loading. Be sure not to have the dashboard up in a browser as that can use significant CPU cycles depending on what widgets you have loaded.</p>
<p dir="auto">Steve</p>
]]></description><link>https://forum.netgate.com/post/811826</link><guid isPermaLink="true">https://forum.netgate.com/post/811826</guid><dc:creator><![CDATA[stephenw10]]></dc:creator><pubDate>Mon, 17 Dec 2018 22:12:39 GMT</pubDate></item><item><title><![CDATA[Reply to Gigabit Throughput on Mon, 17 Dec 2018 21:48:17 GMT]]></title><description><![CDATA[<p dir="auto">Howdy all! So I did purchase a PCIe Intel NIC, but don't see a significant change. What is the best way to test the WAN port with iperf? Is a windows laptop ok?</p>
]]></description><link>https://forum.netgate.com/post/811823</link><guid isPermaLink="true">https://forum.netgate.com/post/811823</guid><dc:creator><![CDATA[TheQuank]]></dc:creator><pubDate>Mon, 17 Dec 2018 21:48:17 GMT</pubDate></item><item><title><![CDATA[Reply to Gigabit Throughput on Sun, 16 Dec 2018 22:48:39 GMT]]></title><description><![CDATA[<p dir="auto">My setup uses a nearly identical Core 2 Due E8500 CPU and I can reliably achieve 900Mbps+ throughput. The network cards make a difference. Also your PC should be fast.  I have an older system based on Xeon W3550, and it never gets more than 600Mbps from Internet, testing with iperf or doing an ISP speed test.</p>
]]></description><link>https://forum.netgate.com/post/811539</link><guid isPermaLink="true">https://forum.netgate.com/post/811539</guid><dc:creator><![CDATA[rm-rf]]></dc:creator><pubDate>Sun, 16 Dec 2018 22:48:39 GMT</pubDate></item><item><title><![CDATA[Reply to Gigabit Throughput on Sun, 16 Dec 2018 14:35:37 GMT]]></title><description><![CDATA[<p dir="auto">Yes, there are lots of public iperf servers you could use. The one you tested against does not appear to be particularly fast, at least not from where you are.</p>
<p dir="auto">But the best test you can do is to run your own server locally on the WAN side.</p>
<p dir="auto">Steve</p>
]]></description><link>https://forum.netgate.com/post/811448</link><guid isPermaLink="true">https://forum.netgate.com/post/811448</guid><dc:creator><![CDATA[stephenw10]]></dc:creator><pubDate>Sun, 16 Dec 2018 14:35:37 GMT</pubDate></item><item><title><![CDATA[Reply to Gigabit Throughput on Sat, 15 Dec 2018 09:19:14 GMT]]></title><description><![CDATA[<p dir="auto">Depend of your location you should try nearest public iperf3 server.<br />
Choose it here: <a href="https://iperf.cc" target="_blank" rel="noopener noreferrer nofollow ugc">https://iperf.cc</a><br />
And try to check your bandwidth again.</p>
]]></description><link>https://forum.netgate.com/post/811317</link><guid isPermaLink="true">https://forum.netgate.com/post/811317</guid><dc:creator><![CDATA[barosso]]></dc:creator><pubDate>Sat, 15 Dec 2018 09:19:14 GMT</pubDate></item><item><title><![CDATA[Reply to Gigabit Throughput on Wed, 12 Dec 2018 20:49:16 GMT]]></title><description><![CDATA[<p dir="auto">see my edit... Put a box on your wan network of pfsense and do your testing...</p>
<p dir="auto">As you can see from that edit - that site is not very reliable for what your speed is or should be..</p>
<p dir="auto">Here just started download of file from one of my servers in the NL... I have a 500mbps connection seeing 53MBps down... My connection is fine - but that scott iperf showing junk..</p>
<p dir="auto"><img src="/assets/uploads/files/1544626409598-speed.png" alt="0_1544626409419_speed.png" class=" img-fluid img-markdown" /></p>
]]></description><link>https://forum.netgate.com/post/810763</link><guid isPermaLink="true">https://forum.netgate.com/post/810763</guid><dc:creator><![CDATA[johnpoz]]></dc:creator><pubDate>Wed, 12 Dec 2018 20:49:16 GMT</pubDate></item><item><title><![CDATA[Reply to Gigabit Throughput on Wed, 12 Dec 2018 20:47:53 GMT]]></title><description><![CDATA[<p dir="auto">testing out to the internet for iperf not really going to be a valid test... Test from your lan to your wan network.. Put a box on your wan and a box on your lan and run iperf between them..</p>
<p dir="auto">Once you go out to the internet you have to many variables to rule out just something on net is problem.. Rule out your local hardware first.  By testing local!!</p>
<pre><code class="language-java">C:\tools\iperf3.6_64bit&gt;iperf3.exe -c iperf.scottlinux.com -p 5201
Connecting to host iperf.scottlinux.com, port 5201
[  5] local 2001:470:&lt;snipped&gt;:7157:1522 port 54061 connected to 2600:3c01::f03c:91ff:fed5:ed33 port 5201
[ ID] Interval           Transfer     Bitrate
[  5]   0.00-1.00   sec  1.50 MBytes  12.6 Mbits/sec
[  5]   1.00-2.00   sec  3.25 MBytes  27.2 Mbits/sec
[  5]   2.00-3.00   sec  2.50 MBytes  21.0 Mbits/sec
[  5]   3.00-4.00   sec  2.25 MBytes  18.9 Mbits/sec
[  5]   4.00-5.00   sec  2.12 MBytes  17.8 Mbits/sec
[  5]   5.00-6.00   sec  1.25 MBytes  10.5 Mbits/sec
[  5]   6.00-7.00   sec   640 KBytes  5.24 Mbits/sec
[  5]   7.00-8.00   sec   896 KBytes  7.34 Mbits/sec
[  5]   8.00-9.00   sec   896 KBytes  7.34 Mbits/sec
[  5]   9.00-10.00  sec  1.25 MBytes  10.5 Mbits/sec
- - - - - - - - - - - - - - - - - - - - - - - - -
[ ID] Interval           Transfer     Bitrate
[  5]   0.00-10.00  sec  16.5 MBytes  13.8 Mbits/sec                  sender
[  5]   0.00-10.09  sec  15.7 MBytes  13.0 Mbits/sec                  receiver

iperf Done.

C:\tools\iperf3.6_64bit&gt;
</code></pre>
<p dir="auto">Just connected to that scott site you used and the speed was utter crap!!!  but I know for a fact my hardware and internet connection are fine.. I see my full pipe all the time downloading and uploading.</p>
]]></description><link>https://forum.netgate.com/post/810684</link><guid isPermaLink="true">https://forum.netgate.com/post/810684</guid><dc:creator><![CDATA[johnpoz]]></dc:creator><pubDate>Wed, 12 Dec 2018 20:47:53 GMT</pubDate></item><item><title><![CDATA[Reply to Gigabit Throughput on Wed, 12 Dec 2018 14:44:14 GMT]]></title><description><![CDATA[<p dir="auto">You have a lot of retries on that first test. Try in the reverse direction. You probably don't need to specify the port, 5201 is the default:<br />
<code>iperf3 -c iperf.scottlinux.com -R</code></p>
<p dir="auto">Run a test to that server from a client connected directly to the modem without pfSense in play. Make sure you can get a reasonable rate to that server over your WAN at all.</p>
<p dir="auto">Steve</p>
]]></description><link>https://forum.netgate.com/post/810682</link><guid isPermaLink="true">https://forum.netgate.com/post/810682</guid><dc:creator><![CDATA[stephenw10]]></dc:creator><pubDate>Wed, 12 Dec 2018 14:44:14 GMT</pubDate></item><item><title><![CDATA[Reply to Gigabit Throughput on Wed, 12 Dec 2018 14:30:06 GMT]]></title><description><![CDATA[<p dir="auto">Howdy all! Sorry I'm a bit behind.  The WAN card was only PCI so I swapped it out with a new PCIx one. So here's what I have now:</p>
<p dir="auto">em0     00:0f:fe:c7:5e:bc   (up) Intel(R) PRO/1000 Network Connection 7.6.1-k<br />
re0     18:a6:f7:01:1e:d0   (up) RealTek 8168/8111 B/C/CP/D/DP/E/F/G PCIe Gigab</p>
<p dir="auto">Here is iperf3 from the pfSense box cmd line with the new PCIx card:</p>
<p dir="auto">root: iperf3 -c iperf.scottlinux.com -p 5201<br />
Connecting to host iperf.scottlinux.com, port 5201<br />
[  5] local 68.102.220.240 port 7956 connected to 45.33.39.39 port 5201<br />
[ ID] Interval           Transfer     Bitrate         Retr  Cwnd<br />
[  5]   0.00-1.01   sec  5.23 MBytes  43.6 Mbits/sec    1   1.41 KBytes<br />
[  5]   1.01-2.00   sec  2.02 MBytes  17.0 Mbits/sec  1397    546 KBytes<br />
[  5]   2.00-3.00   sec   324 KBytes  2.65 Mbits/sec   45   2.85 KBytes<br />
[  5]   3.00-4.00   sec   912 KBytes  7.49 Mbits/sec   19    272 KBytes<br />
[  5]   4.00-5.00   sec  3.93 MBytes  33.0 Mbits/sec    0    288 KBytes<br />
[  5]   5.00-6.00   sec  4.16 MBytes  34.9 Mbits/sec    0    304 KBytes<br />
[  5]   6.00-7.00   sec  3.04 MBytes  25.5 Mbits/sec   14    157 KBytes<br />
[  5]   7.00-8.00   sec  2.35 MBytes  19.7 Mbits/sec    0    174 KBytes<br />
[  5]   8.00-9.00   sec  2.65 MBytes  22.2 Mbits/sec    0    190 KBytes<br />
[  5]   9.00-10.00  sec  2.82 MBytes  23.6 Mbits/sec    0    206 KBytes</p>
<hr />
<p dir="auto">[ ID] Interval           Transfer     Bitrate         Retr<br />
[  5]   0.00-10.00  sec  27.4 MBytes  23.0 Mbits/sec  1476             sender<br />
[  5]   0.00-10.24  sec  25.5 MBytes  20.9 Mbits/sec                  receiver</p>
<p dir="auto">iperf Done.</p>
<p dir="auto">I've not tried flipping the interfaces and trying with the Intel card yet.</p>
<p dir="auto">Here is iperf3 from my desktop:</p>
<p dir="auto">iperf-3.1.3-win64&gt;iperf3.exe -c iperf.scottlinux.com -p 5201<br />
Connecting to host iperf.scottlinux.com, port 5201<br />
[  4] local 192.168.5.121 port 63682 connected to 45.33.39.39 port 5201<br />
[ ID] Interval           Transfer     Bandwidth<br />
[  4]   0.00-1.00   sec  2.12 MBytes  17.8 Mbits/sec<br />
[  4]   1.00-2.00   sec  3.00 MBytes  25.1 Mbits/sec<br />
[  4]   2.00-3.00   sec  3.00 MBytes  25.2 Mbits/sec<br />
[  4]   3.00-4.00   sec  3.00 MBytes  25.2 Mbits/sec<br />
[  4]   4.00-5.00   sec  2.88 MBytes  24.1 Mbits/sec<br />
[  4]   5.00-6.00   sec  3.00 MBytes  25.1 Mbits/sec<br />
[  4]   6.00-7.00   sec  2.88 MBytes  24.1 Mbits/sec<br />
[  4]   7.00-8.00   sec  2.75 MBytes  23.1 Mbits/sec<br />
[  4]   8.00-9.00   sec  3.12 MBytes  26.2 Mbits/sec<br />
[  4]   9.00-10.00  sec  3.00 MBytes  25.2 Mbits/sec</p>
<hr />
<p dir="auto">[ ID] Interval           Transfer     Bandwidth<br />
[  4]   0.00-10.00  sec  28.8 MBytes  24.1 Mbits/sec                  sender<br />
[  4]   0.00-10.00  sec  28.6 MBytes  24.0 Mbits/sec                  receiver</p>
<p dir="auto">iperf Done.</p>
<p dir="auto">Here is my connection from my desktop to the pfSense box:</p>
<p dir="auto">iperf3.exe -c 192.168.5.1 -p 5201<br />
Connecting to host 192.168.5.1, port 5201<br />
[  4] local 192.168.5.121 port 63707 connected to 192.168.5.1 port 5201<br />
[ ID] Interval           Transfer     Bandwidth<br />
[  4]   0.00-1.00   sec   105 MBytes   882 Mbits/sec<br />
[  4]   1.00-2.00   sec   111 MBytes   931 Mbits/sec<br />
[  4]   2.00-3.00   sec   108 MBytes   910 Mbits/sec<br />
[  4]   3.00-4.00   sec   110 MBytes   924 Mbits/sec<br />
[  4]   4.00-5.00   sec   111 MBytes   932 Mbits/sec<br />
[  4]   5.00-6.00   sec   107 MBytes   896 Mbits/sec<br />
[  4]   6.00-7.00   sec   112 MBytes   936 Mbits/sec<br />
[  4]   7.00-8.00   sec   111 MBytes   932 Mbits/sec<br />
[  4]   8.00-9.00   sec   111 MBytes   932 Mbits/sec<br />
[  4]   9.00-10.00  sec  75.5 MBytes   633 Mbits/sec</p>
<hr />
<p dir="auto">[ ID] Interval           Transfer     Bandwidth<br />
[  4]   0.00-10.00  sec  1.04 GBytes   891 Mbits/sec                  sender<br />
[  4]   0.00-10.00  sec  1.04 GBytes   891 Mbits/sec                  receiver</p>
<p dir="auto">iperf Done.</p>
<p dir="auto">Where should I look next?</p>
]]></description><link>https://forum.netgate.com/post/810675</link><guid isPermaLink="true">https://forum.netgate.com/post/810675</guid><dc:creator><![CDATA[TheQuank]]></dc:creator><pubDate>Wed, 12 Dec 2018 14:30:06 GMT</pubDate></item><item><title><![CDATA[Reply to Gigabit Throughput on Wed, 12 Dec 2018 12:00:40 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/netblues">@<bdi>netblues</bdi></a> said in <a href="/post/810585">Gigabit Throughput</a>:</p>
<blockquote>
<p dir="auto">That is competely true, however you get very bad results if mtu is needed to be less and fragmentation doesn;t work.</p>
</blockquote>
<p dir="auto">If that's the case, you should see ICMP "too big" messages.  Fragmentation doesn't happen as often as it used to, as it's not allowed on IPv6 and the do not fragment flag is often used on IPv4.  With Linux, that flag is set on everything, but only TCP on Windows.</p>
]]></description><link>https://forum.netgate.com/post/810640</link><guid isPermaLink="true">https://forum.netgate.com/post/810640</guid><dc:creator><![CDATA[JKnott]]></dc:creator><pubDate>Wed, 12 Dec 2018 12:00:40 GMT</pubDate></item><item><title><![CDATA[Reply to Gigabit Throughput on Wed, 12 Dec 2018 05:15:46 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/jknott">@<bdi>jknott</bdi></a> That is competely true, however you get very bad results if mtu is needed to be less and fragmentation doesn;t work. I doubt its an mtu issue, however the speed differences  via pfsense is huge, and is difficult to believe its the network card unless it is faulty.<br />
A tp link ethernet might not be an intel igb, but still.</p>
]]></description><link>https://forum.netgate.com/post/810585</link><guid isPermaLink="true">https://forum.netgate.com/post/810585</guid><dc:creator><![CDATA[netblues]]></dc:creator><pubDate>Wed, 12 Dec 2018 05:15:46 GMT</pubDate></item><item><title><![CDATA[Reply to Gigabit Throughput on Wed, 12 Dec 2018 02:47:09 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/netblues">@<bdi>netblues</bdi></a> said in <a href="/post/810541">Gigabit Throughput</a>:</p>
<blockquote>
<p dir="auto">Could it be mtu?</p>
</blockquote>
<p dir="auto">Normally, you get the best results with the largest MTU.  That's usually 1500, but would be 1492 on ADSL.</p>
]]></description><link>https://forum.netgate.com/post/810564</link><guid isPermaLink="true">https://forum.netgate.com/post/810564</guid><dc:creator><![CDATA[JKnott]]></dc:creator><pubDate>Wed, 12 Dec 2018 02:47:09 GMT</pubDate></item><item><title><![CDATA[Reply to Gigabit Throughput on Tue, 11 Dec 2018 23:23:30 GMT]]></title><description><![CDATA[<p dir="auto">As expected an old core2duo can route and nat 1 gigabit of traffic.<br />
But the wan results above are horrible.<br />
Something is completely flawed. Could it be mtu? the wan card?<br />
i'd love to see some iperf3 tests cross box with local wan first.</p>
]]></description><link>https://forum.netgate.com/post/810541</link><guid isPermaLink="true">https://forum.netgate.com/post/810541</guid><dc:creator><![CDATA[netblues]]></dc:creator><pubDate>Tue, 11 Dec 2018 23:23:30 GMT</pubDate></item><item><title><![CDATA[Reply to Gigabit Throughput on Wed, 12 Dec 2018 01:52:26 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/marvosa">@<bdi>marvosa</bdi></a> said in <a href="/post/810313">Gigabit Throughput</a>:</p>
<blockquote>
<p dir="auto">1 Gbit firewalled throughput (930-940+ Mbit) over a gigabit WAN?... my vote is no.</p>
</blockquote>
<p dir="auto">Unfortunately I don't have a Gigabit WAN to test with (I can only dream <img src="https://forum.netgate.com/assets/plugins/nodebb-plugin-emoji/emoji/android/1f622.png?v=717669fab53" class="not-responsive emoji emoji-android emoji--cry" style="height:23px;width:auto;vertical-align:middle" title=":cry:" alt="😢" /> ) but in a local test with iperf3 client LAN side and iperf3 server WAN side, firewalling and NATing:</p>
<pre><code>[2.4.4-RELEASE][root@7100.stevew.lan]/root: iperf3 -c 172.21.16.76
Connecting to host 172.21.16.76, port 5201
[  5] local 192.168.112.10 port 47156 connected to 172.21.16.76 port 5201
[ ID] Interval           Transfer     Bitrate         Retr  Cwnd
[  5]   0.00-1.00   sec   112 MBytes   940 Mbits/sec    0    160 KBytes       
[  5]   1.00-2.00   sec   112 MBytes   941 Mbits/sec    0    160 KBytes       
[  5]   2.00-3.00   sec   112 MBytes   941 Mbits/sec    0    160 KBytes       
[  5]   3.00-4.00   sec   112 MBytes   936 Mbits/sec    0    160 KBytes       
[  5]   4.00-5.00   sec   112 MBytes   941 Mbits/sec    0    160 KBytes       
[  5]   5.00-6.00   sec   112 MBytes   941 Mbits/sec    0    160 KBytes       
[  5]   6.00-7.00   sec   111 MBytes   928 Mbits/sec    0    160 KBytes       
[  5]   7.00-8.00   sec   112 MBytes   939 Mbits/sec    0    160 KBytes       
[  5]   8.00-9.00   sec   112 MBytes   941 Mbits/sec    0    160 KBytes       
[  5]   9.00-10.00  sec   112 MBytes   941 Mbits/sec    0    160 KBytes       
- - - - - - - - - - - - - - - - - - - - - - - - -
[ ID] Interval           Transfer     Bitrate         Retr
[  5]   0.00-10.00  sec  1.09 GBytes   939 Mbits/sec    0             sender
[  5]   0.00-10.07  sec  1.09 GBytes   932 Mbits/sec                  receiver

iperf Done.
</code></pre>
<p dir="auto">And during that the E8400 box shows:</p>
<pre><code>last pid: 73219;  load averages:  1.23,  0.80,  0.56                                               up 0+00:31:22  17:23:52
233 processes: 6 running, 184 sleeping, 43 waiting
CPU:  8.0% user,  0.2% nice, 37.3% system, 37.1% interrupt, 17.5% idle
Mem: 348M Active, 243M Inact, 438M Wired, 196M Buf, 888M Free
Swap: 1894M Total, 1894M Free

  PID USERNAME   PRI NICE   SIZE    RES STATE   C   TIME    WCPU COMMAND
  351 root        52    0   224M   191M CPU0    0   0:04  48.39% /usr/local/bin/suricata -i em0 -D -c /usr/local/etc/suric
   56 root        -8    -     0K    16K RUN     0   1:38  37.20% [md1]
   12 root       -92    -     0K   704K CPU0    0   1:53  37.20% [intr{irq261: em1:rx0}]
   12 root       -92    -     0K   704K WAIT    0   2:02  36.76% [intr{irq257: em0:rx0}]
   11 root       155 ki31     0K    32K RUN     1  26:12  18.42% [idle{idle: cpu1}]
   11 root       155 ki31     0K    32K RUN     0  25:13  12.20% [idle{idle: cpu0}]
   12 root       -92    -     0K   704K WAIT    1   0:05   1.52% [intr{irq258: em0:tx0}]
   12 root       -92    -     0K   704K WAIT    1   0:04   1.46% [intr{irq262: em1:tx0}]
  351 root        20    0   224M   191M uwait   1   0:01   1.00% /usr/local/bin/suricata -i em0 -D -c /usr/local/etc/suric
  351 root        20    0   224M   191M uwait   0   0:00   0.61% /usr/local/bin/suricata -i em0 -D -c /usr/local/etc/suric
73735 unbound     20    0 31992K 16828K kqread  0   0:00   0.52% /usr/local/sbin/unbound -c /var/unbound/unbound.conf{unbo
66520 root        37    0 97732K 37496K accept  1   0:01   0.24% php-fpm: pool nginx (php-fpm){php-fpm}
   12 root       -60    -     0K   704K WAIT    1   0:04   0.20% [intr{swi4: clock (0)}]
50995 root        20    0 50952K 39972K nanslp  1   0:00   0.13% /usr/local/bin/php_pfb -f /usr/local/pkg/pfblockerng/pfbl
54344 nobody     -22  r30  6500K  2608K nanslp  1   0:00   0.11% /usr/local/sbin/LCDd -c /usr/local/etc/LCDd.conf -u nobod
   12 root       -72    -     0K   704K WAIT    0   0:00   0.08% [intr{swi1: netisr 1}]
11335 root        20    0  9860K  4360K CPU1    1   0:00   0.08% top -aSH
</code></pre>
<p dir="auto">So I'm going to vote yes. And yes even more if I wasn't running Suricata on that box! <img src="https://forum.netgate.com/assets/plugins/nodebb-plugin-emoji/emoji/android/1f609.png?v=717669fab53" class="not-responsive emoji emoji-android emoji--wink" style="height:23px;width:auto;vertical-align:middle" title=":wink:" alt="😉" /></p>
<p dir="auto">Steve</p>
]]></description><link>https://forum.netgate.com/post/810426</link><guid isPermaLink="true">https://forum.netgate.com/post/810426</guid><dc:creator><![CDATA[stephenw10]]></dc:creator><pubDate>Wed, 12 Dec 2018 01:52:26 GMT</pubDate></item><item><title><![CDATA[Reply to Gigabit Throughput on Tue, 11 Dec 2018 17:04:09 GMT]]></title><description><![CDATA[<p dir="auto">Better to use iperf3. You can install that on pfSense to use from the command line with <code>pkg install iperf3</code>.<br />
You can test reverse using that among other advantages.</p>
<p dir="auto">Testing either from or to the firewall is not a good test as it's optimised for routing not serving but it can still be useful for proving out some things. With iperf3 you can run that test with -R to get the reverse test to prove out the LAN is at least capable of over 280Mbps.</p>
<p dir="auto">You should try testing from your laptop using iperf against speedtest.serverius.net to prove that is a good server to test against. It may be limited to that speed anyway. It would be better to test against a local iperf3 server but otherwise find a public server that can do your WAN line rate when connected directly to the modem.</p>
<p dir="auto">Steve</p>
]]></description><link>https://forum.netgate.com/post/810415</link><guid isPermaLink="true">https://forum.netgate.com/post/810415</guid><dc:creator><![CDATA[stephenw10]]></dc:creator><pubDate>Tue, 11 Dec 2018 17:04:09 GMT</pubDate></item><item><title><![CDATA[Reply to Gigabit Throughput on Tue, 11 Dec 2018 14:49:36 GMT]]></title><description><![CDATA[<p dir="auto">Iperf from cable modem.lan to wan eth?</p>
]]></description><link>https://forum.netgate.com/post/810392</link><guid isPermaLink="true">https://forum.netgate.com/post/810392</guid><dc:creator><![CDATA[netblues]]></dc:creator><pubDate>Tue, 11 Dec 2018 14:49:36 GMT</pubDate></item><item><title><![CDATA[Reply to Gigabit Throughput on Tue, 11 Dec 2018 14:07:12 GMT]]></title><description><![CDATA[<p dir="auto">With such an old system, is the TP-Link card simple PCI or PCIe?</p>
]]></description><link>https://forum.netgate.com/post/810384</link><guid isPermaLink="true">https://forum.netgate.com/post/810384</guid><dc:creator><![CDATA[Grimson]]></dc:creator><pubDate>Tue, 11 Dec 2018 14:07:12 GMT</pubDate></item><item><title><![CDATA[Reply to Gigabit Throughput on Tue, 11 Dec 2018 13:58:54 GMT]]></title><description><![CDATA[<p dir="auto">Morning everyone, thanks for the comments! You'll have to forgive my ignorance as I'm a bit new to measuring throughput. I ran iperf between my desktop computer and the pfSense firewall and got in the 700s:</p>
<h2><a class="anchor-offset" name="root-iperf-c-192.168.5.121-p-5201"></a>/root: iperf -c 192.168.5.121 -p 5201</h2>
<h2><a class="anchor-offset" name="client-connecting-to-192.168.5.121-tcp-port-5201-br-tcp-window-size-64.2-kbyte-default"></a>Client connecting to 192.168.5.121, TCP port 5201<br />
TCP window size: 64.2 KByte (default)</h2>
<p dir="auto">[  3] local 192.168.5.1 port 56750 connected with 192.168.5.121 port 5201</p>
<p dir="auto">write failed: Broken pipe<br />
[ ID] Interval       Transfer     Bandwidth<br />
[  3]  0.0- 9.5 sec   884 MBytes   783 Mbits/sec</p>
<p dir="auto">My desktop is behind three switches and crap wiring.</p>
<p dir="auto">Next, I connected a laptop directly to the cable modem and got in the 800s on speedtest.net several times.</p>
<p dir="auto">Then I attempted to use iperf on pfSense to contact several public servers I found and got results like below several times:</p>
<h2><a class="anchor-offset" name="root-iperf-c-speedtest.serverius.net-p-10"></a>root: iperf -c speedtest.serverius.net -P 10</h2>
<h2><a class="anchor-offset" name="client-connecting-to-speedtest.serverius.net-tcp-port-5001-br-tcp-window-size-64.2-kbyte-default"></a>Client connecting to speedtest.serverius.net, TCP port 5001<br />
TCP window size: 64.2 KByte (default)</h2>
<p dir="auto">[  7] local 68.102.217.178 port 53624 connected with 178.21.16.76 port 5001<br />
[ 11] local 68.102.217.178 port 29834 connected with 178.21.16.76 port 5001<br />
[  5] local 68.102.217.178 port 24828 connected with 178.21.16.76 port 5001<br />
[  9] local 68.102.217.178 port 53592 connected with 178.21.16.76 port 5001<br />
[  3] local 68.102.217.178 port 42250 connected with 178.21.16.76 port 5001<br />
[ 10] local 68.102.217.178 port 44675 connected with 178.21.16.76 port 5001<br />
[  8] local 68.102.217.178 port 52098 connected with 178.21.16.76 port 5001<br />
[ 12] local 68.102.217.178 port 29426 connected with 178.21.16.76 port 5001<br />
[  6] local 68.102.217.178 port 50963 connected with 178.21.16.76 port 5001<br />
[  4] local 68.102.217.178 port 41528 connected with 178.21.16.76 port 5001<br />
[ ID] Interval       Transfer     Bandwidth<br />
[  5]  0.0-10.0 sec  2.75 MBytes  2.30 Mbits/sec<br />
[  8]  0.0-10.1 sec  4.50 MBytes  3.74 Mbits/sec<br />
[ 12]  0.0-10.1 sec  4.38 MBytes  3.64 Mbits/sec<br />
[ 11]  0.0-10.1 sec  4.38 MBytes  3.63 Mbits/sec<br />
[  9]  0.0-10.1 sec  2.75 MBytes  2.28 Mbits/sec<br />
[ 10]  0.0-10.2 sec  4.50 MBytes  3.72 Mbits/sec<br />
[  3]  0.0-10.2 sec  4.50 MBytes  3.71 Mbits/sec<br />
[  6]  0.0-10.2 sec  4.38 MBytes  3.60 Mbits/sec<br />
[  4]  0.0-10.2 sec  4.38 MBytes  3.61 Mbits/sec<br />
[  7]  0.0-10.2 sec  2.75 MBytes  2.26 Mbits/sec<br />
[SUM]  0.0-10.2 sec  39.2 MBytes  32.2 Mbits/sec</p>
<p dir="auto">This is way lower than I got with speedtest.net from the desktop behind all the switches and crap wiring.  so I'm not sure what to think of all this....</p>
<p dir="auto">I did keep an eye on the CPU of the pfSense box during all the tests, and it didn't seem to climb to much.  What should I try next?</p>
]]></description><link>https://forum.netgate.com/post/810380</link><guid isPermaLink="true">https://forum.netgate.com/post/810380</guid><dc:creator><![CDATA[TheQuank]]></dc:creator><pubDate>Tue, 11 Dec 2018 13:58:54 GMT</pubDate></item><item><title><![CDATA[Reply to Gigabit Throughput on Tue, 11 Dec 2018 08:08:12 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/heper">@<bdi>heper</bdi></a> said in <a href="/post/810309">Gigabit Throughput</a>:</p>
<blockquote>
<p dir="auto">the system itself will do that just fine, the TP-link nic will most likely be the culprit</p>
</blockquote>
<p dir="auto">Can it do it mathematically in theory on paper?  Possibly... but the question is... can 11-year-old desktop architecture reliably route and sustain 1 Gbit firewalled throughput (930-940+ Mbit) over a gigabit WAN?... my vote is no.  And that isn't necessarily just my opinion... even the vendor recommends "Server-class Hardware" to push anything over 500 Mbit.</p>
<p dir="auto">Don't get me wrong... I'm not saying the box won't "work"... but it's all a matter of what each person considers acceptable...  will his box route traffic, yes... will it be fast, sure (relatively)... but will it reliably sustain 940+ Mbit/sec of firewalled, real-world traffic over the gigabit WAN he's paying for... my vote is doubtful.  And to me, that's unacceptable.  Barring a misconfiguration that ends up limiting bandwidth by design,  anytime I don't see full bandwidth minus some overhead, I typically start assessing hardware and infrastructure.</p>
]]></description><link>https://forum.netgate.com/post/810313</link><guid isPermaLink="true">https://forum.netgate.com/post/810313</guid><dc:creator><![CDATA[marvosa]]></dc:creator><pubDate>Tue, 11 Dec 2018 08:08:12 GMT</pubDate></item><item><title><![CDATA[Reply to Gigabit Throughput on Tue, 11 Dec 2018 07:48:43 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/heper">@<bdi>heper</bdi></a> Instead of scratching your head, use iperf. You will need two pc with gigabit lan<br />
Boot some dvd linux distro<br />
Mint, debian, fedora, for example<br />
Load/ install iperf and do a few tests<br />
Pc to pc with just a cable<br />
You should get 1g<br />
Pc to pf internal int (run iperf on pf) get 1g</p>
<p dir="auto">Pc to pf external int again measure 1g<br />
If you see 1g everywhere and both ways then your options are</p>
<ol>
<li>Establish plain routing via pf and test</li>
<li>Establish nat via pf and test</li>
<li>Setup a bridge with pf and test</li>
</ol>
<p dir="auto">Do monitor cpu usage on pf whole testing.<br />
At this point you will have clear indications on what might be the issue</p>
<p dir="auto">Apart from that, I would suspect congestion on your provider, but we need to rule out everything else.</p>
]]></description><link>https://forum.netgate.com/post/810312</link><guid isPermaLink="true">https://forum.netgate.com/post/810312</guid><dc:creator><![CDATA[netblues]]></dc:creator><pubDate>Tue, 11 Dec 2018 07:48:43 GMT</pubDate></item><item><title><![CDATA[Reply to Gigabit Throughput on Tue, 11 Dec 2018 07:13:32 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/marvosa">@<bdi>marvosa</bdi></a> said in <a href="/post/810305">Gigabit Throughput</a>:</p>
<blockquote>
<p dir="auto">are we really expecting a 10+ year old desktop with a cheap TP-Link NIC to reliably route and filter traffic @ 1 Gbit throughput?  To me, the logical answer to that question is no.</p>
</blockquote>
<p dir="auto">the system itself will do that just fine, the TP-link nic will most likely be the culprit</p>
]]></description><link>https://forum.netgate.com/post/810309</link><guid isPermaLink="true">https://forum.netgate.com/post/810309</guid><dc:creator><![CDATA[heper]]></dc:creator><pubDate>Tue, 11 Dec 2018 07:13:32 GMT</pubDate></item><item><title><![CDATA[Reply to Gigabit Throughput on Tue, 11 Dec 2018 07:07:09 GMT]]></title><description><![CDATA[<p dir="auto">There are several areas to look at... cables, switch, packages, limiters, traffic shaping, are you virtualized, is the testing box even able to push/pull gigabit speeds, etc, etc... but TBH... you lost me at Core 2 Duo and a TP-Link NIC... ;)</p>
<p dir="auto">The Core 2 Duo E8400 is almost an 11-year-old CPU... which means 11-year-old architecture throughout the box.   Let's all have an honest moment of reflection and think about what the average residential internet speeds were at the beginning of 2008... maybe 10, 20, 30 Mbit if you were lucky?  Now fast forward ~11 years... where 1, 2, and 10 Gbit speeds are available in residential areas ... which is 35-1000 times faster than what was available to most people back then... are we really expecting a 10+ year old desktop with a cheap TP-Link NIC to reliably route and filter traffic @ 1 Gbit throughput?  To me, the logical answer to that question is no.</p>
<p dir="auto">While hardware may not be your only issue... I can almost guarantee it's a contributing factor.  Save yourself the dozens of hours (if not multiple weeks) banging your head against the wall and upgrade your hardware (NIC's included)... then re-assess.</p>
]]></description><link>https://forum.netgate.com/post/810305</link><guid isPermaLink="true">https://forum.netgate.com/post/810305</guid><dc:creator><![CDATA[marvosa]]></dc:creator><pubDate>Tue, 11 Dec 2018 07:07:09 GMT</pubDate></item><item><title><![CDATA[Reply to Gigabit Throughput on Tue, 11 Dec 2018 03:29:16 GMT]]></title><description><![CDATA[<p dir="auto">Ok, well the re NIC isn't going to be helping there but I'd still expect far more than 280Mbps.</p>
<p dir="auto">But how exactly are you testing that?</p>
<p dir="auto">Really I would like to see an iperf3 test with a client on one side of the firewall and server on the other.</p>
<p dir="auto">Steve</p>
]]></description><link>https://forum.netgate.com/post/810283</link><guid isPermaLink="true">https://forum.netgate.com/post/810283</guid><dc:creator><![CDATA[stephenw10]]></dc:creator><pubDate>Tue, 11 Dec 2018 03:29:16 GMT</pubDate></item></channel></rss>