Navigation

    Netgate Discussion Forum
    • Register
    • Login
    • Search
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search

    PfSense very slow - why?

    Firewalling
    4
    7
    2009
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • K
      knebb last edited by

      Hi all,

      I use pfSense in multiple sites and the functionality is perfect.

      I upgraded one site from 6.000DSL to a 100/10Mbit cable connection. The second site was upgraded to 100/30 VDSL line.

      I did a speed test and both sites show huge degration on transfer rate. Site 1 has a maximum value of 30Mbit download and 17Mbit upload. Half of the rate to be expected!
      Nearly the same on the second site. 10Mbit in both directions.

      For testing purposes I attached a laptop directly to the connection- by disconnecting the pfSense firewalls.

      In both cases I received full speed!

      So it appears pfSense drops the connection speed!

      I do not have any special add-ons installed, disabled traffic shaper. Not very much rules, no content filtering by Squid nor anti-virus scanning. Just firewalling. And OpenVPN (which was disabled for the above tests).

      The "hardware" is a virtual machine which has single core (CPU usage is always very low) and 768Mbyte of RAM.

      Anyone having a clue why pfSense throttles the connection speed?

      Greetings

      Christian

      1 Reply Last reply Reply Quote 0
      • johnpoz
        johnpoz LAYER 8 Global Moderator last edited by

        What VM software are you running on?  What is the VM hardware, are there other vms running on this box?  What is the physical connections to the vm host, etc..

        An intelligent man is sometimes forced to be drunk to spend time with his fools
        If you get confused: Listen to the Music Play
        Please don't Chat/PM me for help, unless mod related
        SG-4860 23.01 | Lab VMs CE 2.6, 2.7

        1 Reply Last reply Reply Quote 0
        • K
          knebb last edited by

          @johnpoz:

          What VM software are you running on?  What is the VM hardware, are there other vms running on this box?  What is the physical connections to the vm host, etc..

          Well, I doubt is it related to this. Anyways:
          VMware  ESXi 5.5 running on HP ProLiant MicroServer G8 with QuadCore Hyperthreaded Xeon E3-1265L@2.5GHz
          And yes, there are other VMs running on. But I performed the direct connection test with a Windows VM running on the same host- which got enough resources to use the full bandwidth. Additionally I assigned reservations to the pfSense box so it had exclusive access to physical ressources. Still no change. This is why I doubt it is related to the hypervisor. Network are 2 1GBit ethernet, connected through two HP PRoCurve 1Gbit Switches (1810G).

          Monitoring the pfSense box through "top" during a test run the CPU usage stays very low. Another reason why it appears the VM gets enough ressources.

          Do you need any further details?

          Greetings

          Christian

          1 Reply Last reply Reply Quote 0
          • K
            knebb last edited by

            Hi all,

            embarrassing, indeed.

            I found the reason.

            My laptop is connected through a powerline LAN network. Well, as soon as I attached my laptop to my Ethernet I had full speed of 100Mbit/s through my pfSense box….

            So far about marketing information "500Mbit powerline" .....

            So pfSense is fast enough, all is good....going to install Ethernet cables now...

            /KNEBB

            1 Reply Last reply Reply Quote 0
            • Derelict
              Derelict LAYER 8 Netgate last edited by

              Powerline ethernet sucks. I have never seen it work well. Use MoCA.

              Chattanooga, Tennessee, USA
              The pfSense Book is free of charge!
              DO NOT set a source port in a port forward or firewall rule unless you KNOW you need it!
              Do Not Chat For Help! NO_WAN_EGRESS(TM)

              1 Reply Last reply Reply Quote 0
              • K
                knebb last edited by

                Well, as I did not have any cable to this room I even could not use MoCA….

                But I have every room fitted with ductwork so I was able to install two Cat7 cables and install 1Gbit/s Ethernet now.

                Runs fast as hell now  ;)

                1 Reply Last reply Reply Quote 0
                • W
                  whosmatt last edited by

                  @knebb:

                  Well, as I did not have any cable to this room I even could not use MoCA….

                  But I have every room fitted with ductwork so I was able to install two Cat7 cables and install 1Gbit/s Ethernet now.

                  Runs fast as hell now  ;)

                  There ya go.  And future-proofed as well.

                  1 Reply Last reply Reply Quote 0
                  • First post
                    Last post