<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Mystified by iperf results across IPsec tunnel]]></title><description><![CDATA[<p dir="auto">I am using two installations of pfSense to establish an IPsec tunnel from Verizon Gigabit Fios on the East Coast to Centurylink Gigabit fiber in the inter-mountain West. Here are the basic spec's:</p>
<p dir="auto">On Verizon Fios Gigabit port, I have:<br />
Dual-six core Intel 5650, 8GB RAM (HP DL360 - overkill, I realize)<br />
4 X Broadcom NetExtreme 1000Base-SX (WAN, LAN and 2 spare)</p>
<p dir="auto">On the Centurylink Gigabit fiber port, I have:<br />
2 vCPU Intel 5650, 2GB RAM - Running as a VMware VM<br />
2 X Intel E1000 vNIC's in the VM (WAN and LAN)</p>
<p dir="auto">I recognize the difference in provisioning, but I have never seen the VM become even 20% utilized with RAM or CPU.</p>
<p dir="auto">The IPsec VPN is: Blowfish (256 bits)/SHA1 -  Blowfish (256 bits)/SHA1  (very stable)</p>
<p dir="auto">I have recently been trying to optimize throughput, and been somewhat mystified by the results. When I run:<br />
iperf -c 192.168.100.29                              I might get: [SUM]  0.0-13.6 sec  89.2 MBytes  55.2 Mbits/sec<br />
iperf -c 192.168.100.29 -P 40 -t 60            I might get: SUM]  0.0-63.4 sec  739 MBytes  97.8 Mbits/sec</p>
<p dir="auto">I had previously thought those were pretty good results for any VPN, but then I thought to set-up three clients and three servers and was surprised to see the VPN gracefully handle all of the traffic! Running three of each of the previous tests, I saw almost identical results (simultaneously). In other words: the VPN was pushing 300 Mbps  for 60 seconds at one point. BTW, in all cases iperf is running from CentOS 6 X64m as I never trust Windows TCP/IP stack.</p>
<p dir="auto">Now here is the problem: The VPN is for disaster Recovery and the source and destination Proxies are Windows Server 2008 X64 and I never get throughput greater than 80-100 Mbps.</p>
<p dir="auto">The question: If the VPN can push 300 Mbps (or more) across the WAN, why does a single connection from one IP (at the source) to one IP (at the destination) seem to be limited to 60-100 Mbps?</p>
<p dir="auto">THX,<br />
-J</p>
]]></description><link>https://forum.netgate.com/topic/75370/mystified-by-iperf-results-across-ipsec-tunnel</link><generator>RSS for Node</generator><lastBuildDate>Sat, 18 Jul 2026 18:18:29 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/75370.rss" rel="self" type="application/rss+xml"/><pubDate>Sat, 01 Nov 2014 15:34:37 GMT</pubDate><ttl>60</ttl></channel></rss>