Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    IPSec connection goes stale when high throughput

    Scheduled Pinned Locked Moved IPsec
    23 Posts 4 Posters 2.1k Views 4 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • X Offline
      xylem @NOCling
      last edited by

      @nocling As a test, I disabled the AES-NI CPU Crypto and set up a site-to-site tunnel with the following settings:
      Phase 1:
      AES128-GCM (128 bits) SHA256 14 (2048 bit)
      Phase 2:
      ESP AES256-GCM (128 bits) 14 (2048 bit)

      Now the download does not break anymore. The throughput is about 20 MB/s. Logs after the connection is established are still not available.

      1 Reply Last reply Reply Quote 0
      • N Offline
        NOCling
        last edited by

        Ok, that sounds not good.

        I use Mobike and DPD in P1
        What did you setup in the Advanced IPsec Settings Settings?
        I use:
        Configure Unique IDs as yes
        Make before Break yes
        Asynchronous Cryptography yes

        Netgate 6100 & Netgate 2100

        X 1 Reply Last reply Reply Quote 0
        • X Offline
          xylem @NOCling
          last edited by

          @nocling I have not activated MOBIKE. From my point of view, this is not necessary for a site-to-site VPN connection.

          Here are my P1 Settings:
          Screenshot 2023-01-29 150303.png

          Here are my Advanced IPsec Settings:
          Screenshot 2023-01-29 150111.png

          I also activated Asynchronous Cryptography, but I didn't see any advantages during testing, so I deactivated it again.

          I am at a loss and do not know if the problem is due to the pfSense settings. With the Netgate 1537, do drivers for the hardware also have to be updated in addition to the pfSense? Or is this done with the installation of pfSense? System -> Netgate Firmware Upgrade shows that this function is not available for this hardware.

          1 Reply Last reply Reply Quote 0
          • First post
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.