Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login
    Introducing Netgate Nexus: Multi-Instance Management at Your Fingertips.

    IPSEC Performance on 7100

    Scheduled Pinned Locked Moved IPsec
    7 Posts 4 Posters 152 Views 5 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • N Offline
      Nariolato
      last edited by Nariolato

      Hello everyone, this is my third post. Thank you all for your previous help with migrating from a bridge to a LAG, everything went smoothly.

      I’m back with a new question :) It’s about IPSec performance. I have a 900 Mbps internet connection, and when I run an iperf3 test through this tunnel (from the outside to pfSense), I’m capped at around 400–600 Mbps it fluctuates a lot! (lows of 300 and highs of 700).

      The CPU immediately jumps to ~80%. The issue is that we wanted to run backups through it, but it’s very slow. I’ve already tried a lot of things: MSS Clamping, AES-GCM, QAT, etc. (When we backup the cpu goes to 92%+)

      I’m just wondering if this is normal (I compared it to the IMIX results for the 6100, which seems similar to me, and the results are almost identical).

      All this to figure out if, for my needs, I should switch to an 8200/8300 (by the way, there’s no IMIX test for the 8300) or if the 7100 is supposed to be better and this is a different issue.

      I know I also have peering issues, but I think these are the two bottlenecks.

      Thanks in advance for your answers

      SteveITSS 1 Reply Last reply Reply Quote 0
      • SteveITSS Offline
        SteveITS Rebel Alliance @Nariolato
        last edited by

        @Nariolato can you test to something behind pfSense and not to pfSense itself?

        To upgrade, select your branch in System/Update/Update Settings. When upgrading, allow 10-15 minutes to reboot, or more depending on packages, CPU, and/or disk speed.
        Only install packages for your version of pfSense.
        Upvote 👍 helpful posts!

        N 1 Reply Last reply Reply Quote 0
        • N Offline
          Nariolato @SteveITS
          last edited by

          @SteveITS Yes I've done it, it's the same result (I've tested on 2 hosts behind pfsense).

          Maybe I just don't have the right appliance for what I want to achieve (backup)

          AndyRHA 1 Reply Last reply Reply Quote 0
          • AndyRHA Offline
            AndyRH @Nariolato
            last edited by

            @Nariolato That looks about right to me. When I had a 7100 with a OpenVPN tunnel to a 6100 we could not get above ~700Mb/s. When we could get wiregaurd to work we were in the ~800Mb/s range.

            o|||||||o
            8200

            1 Reply Last reply Reply Quote 0
            • N Offline
              Nariolato
              last edited by

              Imagine I need to backup for ~8 hours because of the size of the backup and the bottlneck of the CPU. Will the 7100 still be alive ? Or any threat of crash ?

              AndyRHA chpalmerC 2 Replies Last reply Reply Quote 0
              • AndyRHA Offline
                AndyRH @Nariolato
                last edited by

                @Nariolato I have been running pfSense >10 years and I have never crashed it by moving data. That is its job.

                o|||||||o
                8200

                1 Reply Last reply Reply Quote 0
                • chpalmerC Offline
                  chpalmer @Nariolato
                  last edited by

                  @Nariolato said in IPSEC Performance on 7100:

                  Imagine I need to backup for ~8 hours because of the size of the backup and the bottlneck of the CPU. Will the 7100 still be alive ? Or any threat of crash ?

                  I have a radio station customer that uses a couple of HP Thinclients from the 2015ish era.. Multiple audio streams and multiple camera streams from the radio transmitter site. They work for years without restart.

                  Triggering snowflakes one by one..
                  Primary- Intel(R) Core(TM) i5-4590T CPU @ 2.00GHz on an M400 WG box. pfSense+
                  Lab Unit- Intel(R) Pentium(R) CPU G4400 @ 3.30GHz on an M470 WG box. pfSense CE 2.8.1

                  1 Reply Last reply Reply Quote 0
                  • First post
                    Last post
                  Copyright 2026 Rubicon Communications LLC (Netgate). All rights reserved.