Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Speed full not handle

    Scheduled Pinned Locked Moved General pfSense Questions
    23 Posts 3 Posters 1.1k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • A
      Antibiotic
      last edited by Antibiotic

      Hi, idk why but pfsense not handle full speed. Tested a lot of speed tests guides. Download speed half of upload speed, 1gb in/1gb out. I do not use for this moment traffic shaping or snort or suricata. Just start going half of my ISP speed for download. Please any tip , what should me check and how?Pfsense 24.03, if any info need I will post here! I did not have this problem on 23.09.
      c3311be2-f752-4e40-830f-513cc4b06748-image.png
      5b3c0812-a908-43c1-af3a-0d4350666c5e-image.png
      3b67e978-96e0-4cc8-8f8c-df1040e1307c-image.png
      5b786952-cc04-481d-adcd-31f2454adab1-image.png
      ceaa3d84-629e-4b4f-98f3-e50a6a05bc40-image.png
      94de82e9-d82b-4243-b3d3-17a3a87438cf-image.png
      b2be763c-1664-4a1c-b6d2-5ad31e633f94-image.png
      1881f4db-8f5b-4adb-a009-b30fb31c02ab-image.png

      A 1 Reply Last reply Reply Quote 0
      • A
        Antibiotic @Antibiotic
        last edited by

        This post is deleted!
        A 1 Reply Last reply Reply Quote 0
        • A
          Antibiotic @Antibiotic
          last edited by

          @Antibiotic Looks like this start going after OpenVPN static route set up on another interface. But not exactly!

          A stephenw10S 2 Replies Last reply Reply Quote 0
          • A
            Antibiotic @Antibiotic
            last edited by

            @Antibiotic
            igc0@pci0:1:0:0: class=0x020000 rev=0x04 hdr=0x00 vendor=0x8086 device=0x 125c subvendor=0x8086 subdevice=0x0000
            vendor = 'Intel Corporation'
            device = 'Ethernet Controller I226-V'
            class = network
            subclass = ethernet
            igc1@pci0:2:0:0: class=0x020000 rev=0x04 hdr=0x00 vendor=0x8086 device=0x 125c subvendor=0x8086 subdevice=0x0000
            vendor = 'Intel Corporation'
            device = 'Ethernet Controller I226-V'
            class = network
            subclass = ethernet
            igc2@pci0:3:0:0: class=0x020000 rev=0x04 hdr=0x00 vendor=0x8086 device=0x 125c subvendor=0x8086 subdevice=0x0000
            vendor = 'Intel Corporation'
            device = 'Ethernet Controller I226-V'
            class = network
            subclass = ethernet
            igc3@pci0:4:0:0: class=0x020000 rev=0x04 hdr=0x00 vendor=0x8086 device=0x 125c subvendor=0x8086 subdevice=0x0000
            vendor = 'Intel Corporation'
            device = 'Ethernet Controller I226-V'
            class = network
            subclass = ethernet

            1 Reply Last reply Reply Quote 0
            • stephenw10S
              stephenw10 Netgate Administrator @Antibiotic
              last edited by

              @Antibiotic said in Speed full not handle:

              @Antibiotic Looks like this start going after OpenVPN static route set up on another interface. But not exactly!

              So without the OpenVPN configured you get the full download speed?

              A 1 Reply Last reply Reply Quote 0
              • A
                Antibiotic @stephenw10
                last edited by Antibiotic

                @stephenw10 Yes, just checked out. If disable OpenVPN clients and test speed on LAN ,interface without OpenVPN use. I have full speed up/down. How to resolve this?

                1 Reply Last reply Reply Quote 0
                • provelsP
                  provels
                  last edited by

                  Isn't OpenVPN still single threaded? I supposed encryption levels could enter into the equation. too. What's the CPU load like when on OpenVPN?

                  Peder

                  MAIN - pfSense+ 24.11-RELEASE - Adlink MXE-5401, i7, 16 GB RAM, 64 GB SSD. 500 GB HDD for SyslogNG
                  BACKUP - pfSense+ 23.01-RELEASE - Hyper-V Virtual Machine, Gen 1, 2 v-CPUs, 3 GB RAM, 8GB VHDX (Dynamic)

                  A 2 Replies Last reply Reply Quote 0
                  • A
                    Antibiotic @provels
                    last edited by Antibiotic

                    @provels CPU load minimum, but even on interface with OpenVPN have a speed 500/500 . Lan have download only about 250/300. LAN do not use OpenVPN. If OPenVPN clients switched off LAN have almost 1gb up/down

                    1 Reply Last reply Reply Quote 0
                    • A
                      Antibiotic @provels
                      last edited by

                      @provels said in Speed full not handle:

                      Isn't OpenVPN still single threaded?

                      Sorry. idk how to check this

                      1 Reply Last reply Reply Quote 0
                      • stephenw10S
                        stephenw10 Netgate Administrator
                        last edited by

                        Hmm, I'm unclear what the situation here is.

                        Your config doesn't look like any LAN traffic would be using a VPN anyway?

                        Are you saying that the slow downloads are over the VPN tunnel?

                        A 1 Reply Last reply Reply Quote 0
                        • A
                          Antibiotic @stephenw10
                          last edited by Antibiotic

                          @stephenw10 Negative, with vpn clients ON , the interface whom do not use any VPN, speed test show low download speed. When clients is OFF , interface without VPN speed is OK. Looks like problem with routing. Is it a bug?

                          56ee23e3-65ef-4493-847e-0c0e1cdee41c-image.png

                          192.168.10.1 LAN

                          When stop services OpenVPN, LAN speed become as should be 1gb up/down

                          A 1 Reply Last reply Reply Quote 0
                          • A
                            Antibiotic @Antibiotic
                            last edited by

                            @Antibiotic
                            I'm open ticket in TAC lite support. Will see !

                            A 1 Reply Last reply Reply Quote 0
                            • A
                              Antibiotic @Antibiotic
                              last edited by Antibiotic

                              @Antibiotic
                              Very strength, if make a firewall rule to reject routing to VPN gateway on LAN( this interface DO NOT use OpenVPN) lost internet connection. IDK why, but pfsense thinking that LAN also going over OpenVPN gateway, but FORCE set to going over ISP gateway!

                              1 Reply Last reply Reply Quote 0
                              • stephenw10S
                                stephenw10 Netgate Administrator
                                last edited by

                                You do have the System default gateway set to automatic so that may switch to the VPN when it connects. Try setting the default gateway to WANGW.

                                A 1 Reply Last reply Reply Quote 0
                                • A
                                  Antibiotic @stephenw10
                                  last edited by

                                  @stephenw10
                                  I did, but does not assist(((

                                  1 Reply Last reply Reply Quote 0
                                  • stephenw10S
                                    stephenw10 Netgate Administrator
                                    last edited by

                                    So is any other traffic going over the VPN when they are enabled?

                                    When the VPN is not enabled do you see full download speeds from the firewall itself?

                                    A 1 Reply Last reply Reply Quote 0
                                    • A
                                      Antibiotic @stephenw10
                                      last edited by Antibiotic

                                      @stephenw10 Idk, how to explain better. I will try, looks like all traffic going over VPN, if even not all interfaces use vpn. Routing all traffic over VPN gateway by my opinion. Pfsense routing over WAN do not see or not working. When i switch off vpn client and measuring speed on interface whom not belong routing to vpn gateway internet speed become normal. When i switch on vpn client and measuring speed on interface whom not belong to vpn gateway speed become like me using vpn here.

                                      1 Reply Last reply Reply Quote 0
                                      • stephenw10S
                                        stephenw10 Netgate Administrator
                                        last edited by

                                        Do you have the OpenVPN client set to pull a default route?

                                        Check the routing table.

                                        A 2 Replies Last reply Reply Quote 0
                                        • A
                                          Antibiotic @stephenw10
                                          last edited by

                                          @stephenw10

                                          89793765-9e36-4dd6-b6aa-0c2e6287e2b7-image.png

                                          1 Reply Last reply Reply Quote 0
                                          • A
                                            Antibiotic @stephenw10
                                            last edited by

                                            @stephenw10 Screenshot_22-5-2024_16155_192.168.20.1.jpeg

                                            1 Reply Last reply Reply Quote 0
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.