Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Recommended maximum number of simultaneous client connections for a client to site OpenVPN?

    Scheduled Pinned Locked Moved OpenVPN
    6 Posts 3 Posters 947 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • B
      bp81
      last edited by

      As the title asks. The device in question is a Netgate 6100. At what point do VPN connections start to bring down the router's performance significantly? I would expect the number to be around 20 most of the time, with a couple of spikes once or twice a year to around 100.

      This would be an always up tunnel running on our windows workstations for the purposes of always having remote management capabilities.

      R 1 Reply Last reply Reply Quote 0
      • R
        rcoleman-netgate Netgate @bp81
        last edited by

        @bp81 The simultaneous is per credential if you are doing 1 credential and expect 20+ users on that you might want to reconsider your approach -- if you have to change the credential method then everyone has to update.

        Better to have 20 users credentials and give them 1 connection. Or 2 if you need a mobile device.

        Ryan
        Repeat, after me: MESH IS THE DEVIL! MESH IS THE DEVIL!
        Requesting firmware for your Netgate device? https://go.netgate.com
        Switching: Mikrotik, Netgear, Extreme
        Wireless: Aruba, Ubiquiti

        B 1 Reply Last reply Reply Quote 0
        • B
          bp81 @rcoleman-netgate
          last edited by

          @rcoleman-netgate said in Recommended maximum number of simultaneous client connections for a client to site OpenVPN?:

          @bp81 The simultaneous is per credential if you are doing 1 credential and expect 20+ users on that you might want to reconsider your approach -- if you have to change the credential method then everyone has to update.

          Better to have 20 users credentials and give them 1 connection. Or 2 if you need a mobile device.

          This is what we are doing. Specifically, it will be certificate authentication with one unique certificate per workstation.

          R 1 Reply Last reply Reply Quote 0
          • R
            rcoleman-netgate Netgate @bp81
            last edited by

            @bp81 Then one is fine.

            Ryan
            Repeat, after me: MESH IS THE DEVIL! MESH IS THE DEVIL!
            Requesting firmware for your Netgate device? https://go.netgate.com
            Switching: Mikrotik, Netgear, Extreme
            Wireless: Aruba, Ubiquiti

            B 1 Reply Last reply Reply Quote 0
            • B
              bp81 @rcoleman-netgate
              last edited by

              @rcoleman-netgate said in Recommended maximum number of simultaneous client connections for a client to site OpenVPN?:

              @bp81 Then one is fine.

              Maybe I didn't ask the question correctly.

              How many tunnels can I have up and running, with light to moderate activity on those tunnels, before I start bogging down the router? One tunnel per workstation. On an average day I expect to have 20 tunnels running simultaneously, with occasional spikes to 100. This would be running on a Netgate 6100.

              Dobby_D 1 Reply Last reply Reply Quote 0
              • Dobby_D
                Dobby_ @bp81
                last edited by

                @bp81

                It all depends also on what are the workstations are doing through the tunnels! As an example, you have 20 tunnels
                and heavy load on (through) them and this is like 50
                tunnels and more with only some small traffic through them.

                No one of us is able to answer this question without knowing what traffic and how much traffic is running through that tunnels.

                #~. @Dobby

                Turris Omnia - 4 Ports - 2 GB RAM / TurrisOS 7 Release (Btrfs)
                PC Engines APU4D4 - 4 Ports - 4 GB RAM / pfSense CE 2.7.2 Release (ZFS)
                PC Engines APU6B4 - 4 Ports - 4 GB RAM / pfSense+ (Plus) 24.03_1 Release (ZFS)

                1 Reply Last reply Reply Quote 0
                • First post
                  Last post
                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.