Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Firewall Engreess Rule slows upload speed!

    Scheduled Pinned Locked Moved Firewalling
    6 Posts 3 Posters 998 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • J
      jpinder70
      last edited by

      Hi,

      I have a rules setup to allow only ports (80,443,3389,21,53) outbound - this works perfectly and I get internet and my download speed is ok but my upload speed is cut in 1/2 and my ping times go up.

      Any Idea what's causing this?

      Test 1 speed test done with the rule to allow all traffic and any protocol to all destination and I get 100Mpbs/100Mpbs - Overhead

      Test 2 speed test done with the rules to allow only (80,443,3389,21,53) destination ports and I get 100Mpbs/50Mpbs - Overhead

      without_engress_rule.PNG
      without_engress_rule.PNG_thumb
      engress_with_rule.PNG
      engress_with_rule.PNG_thumb

      1 Reply Last reply Reply Quote 0
      • H
        Harvy66
        last edited by

        I assume by egress rule, you mean an ingress rule on your LAN interface? Could you post the rules and other info about your network?

        1 Reply Last reply Reply Quote 0
        • johnpozJ
          johnpoz LAYER 8 Global Moderator
          last edited by

          Are you testing to the same server?  Why did you download jump to 121 vs 99, and your ping time went from 13 to 19??

          Traffic to speedtest is going to be 80, and icmp - so your also allowing icmp I take it ;)  So you ran these tests multiple times and they are repeatable? Because it makes no sense.  Do you have other traffic going on during your tests?  Be it allowed or blocked?

          An intelligent man is sometimes forced to be drunk to spend time with his fools
          If you get confused: Listen to the Music Play
          Please don't Chat/PM me for help, unless mod related
          SG-4860 24.11 | Lab VMs 2.7.2, 24.11

          1 Reply Last reply Reply Quote 0
          • J
            jpinder70
            last edited by

            OK… Here's the breakdown and sorry I meant ingress.

            • I have 1Gbps WAN up/down
            • 10 VLAN on a 10Gbps

            Each VLAN is 100Mpbs up/down

            If I allow IPv4* * * * I get 100Mpbs up/down  with no issues

            If I only allow ports (80,443,3389,53 and 21), ICMP and I get 100Mpbs down but only 50Mpbs up

            I can reproduce this issue at all 10 Locations on the VLAN Interface, If there's no ingress filter I get 100Mpbs/100Mpbs - overhead.

            These tests were done during after hours and we have a Fiber connection between each sites, that can burst to 200Mpbs if needed.

            Thanks for the replies

            ingress_allow_works.PNG
            ingress_allow_works.PNG_thumb
            ingress_allow_nowork.PNG
            ingress_allow_nowork.PNG_thumb

            1 Reply Last reply Reply Quote 0
            • J
              jpinder70
              last edited by

              Any help please

              1 Reply Last reply Reply Quote 0
              • johnpozJ
                johnpoz LAYER 8 Global Moderator
                last edited by

                And where are you testing to speedtest.net?  You do understand they normally use 8080 as the port for testing..  If you have only 80 open, then is prob using some other test method that maybe can not handle 100mbps up?

                And by the way your 3rd rule there is pointless..  Your allowing traffic to same network as your source..

                Add 8080 to your rule, what does it do now?  Also you say this is repeatable - so you get the same results at multiple test sites?  Lets see off the top of my head testmy.net speedof.me netalyzr.icsi.berkeley.edu plenty of others as well

                An intelligent man is sometimes forced to be drunk to spend time with his fools
                If you get confused: Listen to the Music Play
                Please don't Chat/PM me for help, unless mod related
                SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                1 Reply Last reply Reply Quote 0
                • First post
                  Last post
                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.