Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    pfSense is slowing down my internet

    Scheduled Pinned Locked Moved General pfSense Questions
    9 Posts 4 Posters 1.1k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • J
      JohnnyBeGood
      last edited by JohnnyBeGood

      Hey all,

      I have Netgate SG-3100 connected to Xfinity rented modem with gigabit internet package. Before that I owned the modem and thought speed issue were due to bad modem.
      When connected directly to the modem using desktop computer I get full speed:

      22248222-9411-4c72-9ad3-0e22ed80ab35-image.png

      When I connect pfSense to it my download speed is cut in half:

      89403179-19b8-47d9-8e05-85abeda17e01-image.png

      I've tried toggling Disable hardware checksum offload and rebooted
      as suggested here but no joy.

      Can someone please share their experience how they fixed this issue?

      Here's the list of installed packages:

      9bacbf23-5e0e-4f1b-9530-77a5d4153e4a-image.png

      Output of speedtest-cli

      [2.4.5-RELEASE][root@pfSense.mydomain.net]/root: speedtest-cli
      Retrieving speedtest.net configuration...
      Testing from Comcast Cable (73.xxx.xx.xxx)...
      Retrieving speedtest.net server list...
      Selecting best server based on ping...
      Hosted by Speedtest.net (Seattle, WA) [32.11 km]: 30.4 ms
      Testing download speed................................................................................
      Download: 434.61 Mbit/s
      Testing upload speed................................................................................................
      Upload: 25.91 Mbit/s
      [2.4.5-RELEASE][root@pfSense.mydomain.net]/root:
      

      I like to fill my tub up with water, then turn the shower on and act like I'm in a submarine that's been hit!

      1 Reply Last reply Reply Quote 0
      • B
        beachbum2021
        last edited by

        comcast modem in bridged mode?

        J 1 Reply Last reply Reply Quote 0
        • J
          JohnnyBeGood @beachbum2021
          last edited by

          @beachbum2021 said in pfSense is slowing down my internet:

          comcast modem in bridged mode?

          Yes!

          I like to fill my tub up with water, then turn the shower on and act like I'm in a submarine that's been hit!

          1 Reply Last reply Reply Quote 0
          • B
            beachbum2021
            last edited by

            i had a similar issue and found it to be ntop. Even then, on a 1gb comcast line I only get 700ish down hardwired. If i direct connect I get 950down. I also have a 3100. I'm not entirely sure why the netgate device does this either. When I was running ntop I saw pretty much the same speed as you. try resetting the modem and netgate again. I use a SB8200 modem.

            1 Reply Last reply Reply Quote 0
            • B
              beachbum2021
              last edited by beachbum2021

              if it makes you feel any better..1GB line-in and I get those speed (950 down)with the 3100 out of the equation. That said, I'm not sure I entirely understand where the issue lies if the 3100 can process more than 1GB throughput.
              1st test
              cfac5d16-4d86-472a-af29-ed6e7968260d-image.png
              2nd test
              5c947076-5fbc-451a-8b5f-79274ba3a9c6-image.png

              1 Reply Last reply Reply Quote 0
              • keyserK
                keyser Rebel Alliance
                last edited by

                Your issue is the traffic “inspection” packages installed:

                BandwidthD
                DarkStat
                Status_Traffic_Totals

                These packages put the Network Interface in Promiscious mode to get “copies”/access to frames sent and delivered on the interface. Promiscious mode requires copious amounts of CPU time to deliver and process frames within the software packages - something the ARM based appliances does not have. So effectively it kills throughput on your SG-3100. On 3100 it takes about half of the Gigabit throughput (just like what you are seeing). On the smaller SG-1100 and SG-2100 it takes slightly more than half (putting them @ about 200mbit).

                Uninstall those packages and your bandwidth will return to the promised 930ish mbit through pfSense.
                If you need those packages running, you have to get a bigger appliance - and so far an Intel based one. They can handle that load.

                Love the no fuss of using the official appliances :-)

                1 Reply Last reply Reply Quote 1
                • J
                  JohnnyBeGood
                  last edited by

                  Thank you all for the replies!

                  I removed all packages and left only:
                  openvpn-cleint-export
                  pfBlockerNG-devel

                  Did reboot and tested again. Still no joy. I was getting same speeds.
                  I had Shuttle DS437 with:
                  Intel Celeron CPU 1037U @ 1.80GHz
                  Samsung 256GB SSD
                  8GB of RAM.
                  Installed fresh copy of pfSense and was getting same speeds.
                  I was so frustrated that I downloaded Untangle and installed it on the Shuttle and I'm getting 900Mbps+ now.

                  I'm using pfSense over 10+ years but with this I have to think about selling SG-3100 because even if I bought SG-5100 my speeds would not be above 900.

                  If anyone has more ideas what to try I would be more than happy because I would love to continue to support pfSense!

                  I like to fill my tub up with water, then turn the shower on and act like I'm in a submarine that's been hit!

                  1 Reply Last reply Reply Quote 0
                  • GertjanG
                    Gertjan
                    last edited by

                    See also : https://forum.netgate.com/topic/142894/comcast-gigabit-sg-3100-not-getting-gig-speed

                    A test on reddit - see also the video - from 2018 shows 900+ over WAN.
                    That is, the other ipferf3 side was on the WAN network, so the traffic was going through pfSense, version 2.4.3.
                    https://www.reddit.com/r/PFSENSE/comments/88f2ty/netgate_sg3100_teardown_speedtest_review_of_this/

                    No "help me" PM's please. Use the forum, the community will thank you.
                    Edit : and where are the logs ??

                    1 Reply Last reply Reply Quote 0
                    • B
                      beachbum2021
                      last edited by

                      i've tested again, here are my stats. 1GB down @ Comcrap. I'm happy with this throughput considering suricata/extensive pfblocker lists.

                      52a984fe-fe15-4ae7-8d16-05117685f590-image.png
                      0af8c970-3f1f-4b94-99cf-deaeb7ef953a-image.png
                      2f696e8a-bd99-4b0f-b419-d60bbc2a9695-image.png

                      1 Reply Last reply Reply Quote 0
                      • First post
                        Last post
                      Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.