Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Diagnosing pfSense performance loss (40%)

    Scheduled Pinned Locked Moved General pfSense Questions
    10 Posts 3 Posters 806 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • J
      jkamal
      last edited by

      Hi all,

      After resolving a thorny NAT issue that was entirely my fault, I've come up with this issue, the bandwidth delivered by my pfSense appliance is suffering over 50% download loss. ISP provides 150mbps, computer connected directly to cable modem gets 150mbps. My pfSense device, connected to the cabler modem, is only delivering about 67mbps to my PC connected to the pfsense device in LAN.

      If anyone can offer some advice on how to resolve what might be causing this performance loss I would be eternally grateful!

      The pfsense device is running
      72a9670d-2e70-4347-839f-130ff0e9df58-image.png

      1 Reply Last reply Reply Quote 0
      • J
        jkamal
        last edited by

        Packages:
        e66f0a9d-d9b4-4151-9457-e087b8a71b3b-image.png

        Of these, the iperf one is not in actual use at the moment but it is installed. There is no active VPN server.

        1 Reply Last reply Reply Quote 0
        • J
          jkamal
          last edited by

          Following the troubleshooting guide, this is the System-advanced-networking config:
          5139f1f3-a019-462d-98b2-ecc5e9ce841c-image.png

          No changes were needed, default was set. Issue still persists though of course. :-)

          1 Reply Last reply Reply Quote 0
          • KOMK
            KOM
            last edited by

            Is this the guide you're referring to? Have you gone through it completely?

            https://docs.netgate.com/pfsense/en/latest/interfaces/low-throughput-troubleshooting.html

            1 Reply Last reply Reply Quote 0
            • J
              jkamal
              last edited by jkamal

              Yes that is the guide!

              The main part I haven't tried to do yet is the MTU/MSS part. If I understand correctly, this would involve me contacting my ISP to determine what the optimal settings are for this?

              There is no traffic shaping applied.

              My PC connected to the pf-LAN is using CAT6 wired. Tested by reconnecting directly to the cable-modem and the speed there is 150mbps, drop in speed only occurs when connected to the pf device. Repeated multiple times to rule out other potential issues (like a windows update download sneaking in).

              Also tested ISP performance using a laptop connected by WiFi, and that is a solid 150mbs (thruj 802.11ac) connection.

              Getting the ISP to answer MTU/MSS settings may not be a fun process, was trying to avoid this. :-)

              NogBadTheBadN 1 Reply Last reply Reply Quote 0
              • NogBadTheBadN
                NogBadTheBad @jkamal
                last edited by

                @jkamal said in Diagnosing pfSense performance loss (40%):

                Also tested ISP performance using a laptop connected by WiFi, and that is a solid 150mbs (thruj 802.11ac) connection.

                Is that WiFi connected to your pfSense router, if it is its not an issue with your WAN connection.

                Andy

                1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

                1 Reply Last reply Reply Quote 0
                • J
                  jkamal
                  last edited by

                  No, the laptop by WiFi is using the cable-modem WiFi.

                  pfsense network is wired only, and has only two connections -> to cable modem [wan1], and to my PC [lan]. Nothing else..

                  1 Reply Last reply Reply Quote 0
                  • NogBadTheBadN
                    NogBadTheBad
                    last edited by NogBadTheBad

                    You'll see the MTU if you start a download of a big file and do a packet capture on your WAN interface.

                    Download the file then open it in Wireshark.

                    Screenshot 2019-06-10 at 19.40.41.png

                    It you have ISP Router -> pfSense Router I'd have expected it to be 1500, expecially as it works fine on Wi-Fi.

                    You'll have a double NAT that won't help.

                    Also are you bridging, you've mentioned it in other posts?

                    https://forum.netgate.com/topic/143855/assistance-enabling-external-access-into-lan-nat-port-forwarding

                    Andy

                    1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

                    1 Reply Last reply Reply Quote 0
                    • J
                      jkamal
                      last edited by

                      I killed the bridge -- did a total reset to factory, and reconfigured everything. Only three ports are defined now, with three unassigned. igb0 is wan1, igb1 is wan2 (disabled right now), and igb2 is LAN.

                      1 Reply Last reply Reply Quote 0
                      • J
                        jkamal
                        last edited by

                        Isolated the issue! During testing, I had misconfigured my cable-modem ISP. A hard reset of the cable modem and a switch back to DHCP on pfsense wan-1 interface cured the issue.

                        Not sure how it was providing 50% connection, as everything was messed up.... :-)

                        Full capacity restored!!

                        1 Reply Last reply Reply Quote 1
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.