Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    SMB sharing performances through iPsec VPN with nat 1:1

    Scheduled Pinned Locked Moved General pfSense Questions
    4 Posts 3 Posters 282 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • A
      AxelTwin
      last edited by AxelTwin

      Hi everybody,

      Heres is the configuration:
      We have a dedicated server with proxmox installed on it. This proxmox hosts a VM with pFsense and multiple lxc containers with customers's files behind the pfsense.
      Every single customers has a firewall on site which is connected to the pFsense through an iPsec tunnel with a public ip address binded to a container's private ip with nat 1:1, so they can access their files through this tunnel using a unique public ip. They are using smb protocol to access those files.
      We noticed that while accessing files is pretty fast, copying files has a very very low speed rate even with a 100mb/s internet connexion on both side, and it looks like pfsense is not able to process quickly this task given this configuration.
      Any suggestions to improve performances ?

      1 Reply Last reply Reply Quote 0
      • kiokomanK
        kiokoman LAYER 8
        last edited by

        how fast/slow we are talking?
        could be speed and duplex settings on the interfaces
        could be MTU
        could be packet loss
        ....
        you should use something like wireshark to see what's going wrong

        ̿' ̿'\̵͇̿̿\з=(◕_◕)=ε/̵͇̿̿/'̿'̿ ̿
        Please do not use chat/PM to ask for help
        we must focus on silencing this @guest character. we must make up lies and alter the copyrights !
        Don't forget to Upvote with the 👍 button for any post you find to be helpful.

        1 Reply Last reply Reply Quote 0
        • A
          AxelTwin
          last edited by AxelTwin

          we are talking of a 100ko/s average
          MTU & duplex settings checked already on both sides
          (MTU=1500 / MSS=1460)

          Also, remote people can also access their files connecting from a laptop with openvpn.
          same process: ovpn -> pfsense public ip -> nat 1:1 -> lxc container private ip
          Still very slow transfer speed rate

          1 Reply Last reply Reply Quote 0
          • stephenw10S
            stephenw10 Netgate Administrator
            last edited by

            What latency do clients see to the file stores?

            smb is notoriously terrible over high latency links. What speeds do they see if they try pulling files in some other way? SCP for example?

            I would still try enabling mss clamping in IPSec as a test.

            Steve

            1 Reply Last reply Reply Quote 0
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.