Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    What's wrong with my ipsec?

    Scheduled Pinned Locked Moved IPsec
    10 Posts 3 Posters 1.2k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • C
      ciozhe
      last edited by

      With Fortigate 60E to pfsense(in my office), ipsec can work in my full wan speed.
      I have 1Gbps line, so I got a N5105box and created a pfsense gateway to replace the Fortigate, but the ipsec speed only has full speed at begining when I copy files by SMB, can anybody help me? I tried ESXi6.7, ESXi7, ESXi8, same result.
      ef7a66ab-bb44-491d-a72a-5291bb974fb4-图片.png bbefbd4c-6db0-4211-b65b-bd19887ebeea-图片.png
      399b5442-46d5-4678-aef1-b89faeb317bc-图片.png

      V 1 Reply Last reply Reply Quote 0
      • C
        ciozhe
        last edited by

        I used an 200m adsl line for the above test, and used the same Pfense box the office side. I don't have more firewall rules than the ipsec one.

        G 1 Reply Last reply Reply Quote 0
        • G
          gabacho4 Rebel Alliance @ciozhe
          last edited by

          @ciozhe I notice that your pfsense instance has neither aes-ni or QAT which means you are not getting any hardware acceleration. Perhaps the fortigate did benefit from one of those features?

          1 Reply Last reply Reply Quote 1
          • V
            viragomann @ciozhe
            last edited by

            @ciozhe
            You have to enable AES-NI hardware accelaration in System > Advanced > Miscellaneous > Cryptographic Hardware and reboot the box.

            1 Reply Last reply Reply Quote 1
            • C
              ciozhe
              last edited by

              My hardware support aes-in, I enabled it and restarted the Pfsense, but seems no change.
              fc6cab19-e033-478e-b80a-d63137a90f55-图片.png

              V 1 Reply Last reply Reply Quote 0
              • V
                viragomann @ciozhe
                last edited by

                @ciozhe
                What encryption algorithm are you using in the IPSec?

                The AES-GCM should provide best performance with AES-NI set.

                1 Reply Last reply Reply Quote 0
                • C
                  ciozhe
                  last edited by

                  f3bd65ef-b9d6-4de2-bc55-e23787c96ca1-image.png
                  also tried other encryption protocols, but no luck.

                  1 Reply Last reply Reply Quote 0
                  • G
                    gabacho4 Rebel Alliance
                    last edited by

                    I have to wonder if it has something to do with the fact that you are running a virtualized instance of pfsense versus bare metal. Seems like there is always some sort of tweak required when running virtually. I have no experience with that however as I prefer to run my routers on bare metal.

                    C 1 Reply Last reply Reply Quote 1
                    • C
                      ciozhe @gabacho4
                      last edited by

                      @gabacho4, thanks a lot. using nic passthrough in ESXi and aes-in enabled in PFsense, I get much better speed now:
                      993e2b1f-691e-4365-b67a-d1913b2d0921-image.png

                      1 Reply Last reply Reply Quote 0
                      • C
                        ciozhe
                        last edited by

                        BTW, this is not for me:
                        03a3bfdb-92a9-437a-88f5-90c7db833c2b-image.png

                        I get best ipsec performance by these:
                        3f5503cf-ce81-4ef8-adff-d4a82a611547-image.png

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.