ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    pfSense slow site-to-site VPN

    Scheduled Pinned Locked Moved IT Discussion
    freebsdpfpfsenseopenvpnvpnsslssl vpnnetworking
    19 Posts 7 Posters 9.7k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • thwrT
      thwr @scottalanmiller
      last edited by

      @scottalanmiller good point, thanks

      1 Reply Last reply Reply Quote 0
      • J
        Jason Banned @IT-ADMIN
        last edited by

        @IT-ADMIN said in pfSense slow site-to-site VPN:

        before continue reading your issue, i want to tell you that pfsense will not play well in virtual environment, in their official website too many people complaining about slow connection when installing pfsense in virtual environment,

        That used to be the case, newest versions are fine.

        scottalanmillerS 1 Reply Last reply Reply Quote 1
        • J
          Jason Banned
          last edited by

          Why Open VPN for site to Site over IPSEC? OpenVPN is normally much slower..

          OpenVPN was more made for easy configuration.

          thwrT scottalanmillerS 2 Replies Last reply Reply Quote 1
          • J
            Jason Banned
            last edited by

            Also have you considered TINC full mesh on Pfsense, I have used it in the past when I worked at smaller companies.

            thwrT 1 Reply Last reply Reply Quote 0
            • thwrT
              thwr @Jason
              last edited by

              @Jason said in pfSense slow site-to-site VPN:

              OpenVPN is normally much slower..

              No preference for OpenVPN, tried both, IPsec being just 1MB/s faster. Oddly, latency is still great while throughput is low. Both lines are sync 1GB/s, just some fiber and roughly 4 km / 2.5 miles in between. Next to no reflections on the fibre.

              Async lines are a known problem especially in OpenVPN, but that shouldn't be the case 😉

              1 Reply Last reply Reply Quote 0
              • thwrT
                thwr @Jason
                last edited by

                @Jason Not yet. Problem is, there's some confidential data going over that wire. Sure, already encrypted on OSI-7, but I don't feel comfortable using a solution in this context I don't know. Would rather like to stick to IPsec (preferred) or OpenVPN.

                1 Reply Last reply Reply Quote 0
                • scottalanmillerS
                  scottalanmiller @Jason
                  last edited by

                  @Jason said in pfSense slow site-to-site VPN:

                  @IT-ADMIN said in pfSense slow site-to-site VPN:

                  before continue reading your issue, i want to tell you that pfsense will not play well in virtual environment, in their official website too many people complaining about slow connection when installing pfsense in virtual environment,

                  That used to be the case, newest versions are fine.

                  Does it have built in PV drivers for most platforms? Which ones does it support well?

                  1 Reply Last reply Reply Quote 0
                  • scottalanmillerS
                    scottalanmiller @Jason
                    last edited by

                    @Jason said in pfSense slow site-to-site VPN:

                    Why Open VPN for site to Site over IPSEC? OpenVPN is normally much slower..

                    Specifically in CPU usage.

                    1 Reply Last reply Reply Quote 1
                    • M
                      marcinozga
                      last edited by

                      Try this: https://forum.pfsense.org/index.php?topic=47567.0

                      What's your protocol set to? TCP or UDP?

                      thwrT 1 Reply Last reply Reply Quote 2
                      • thwrT
                        thwr @marcinozga
                        last edited by thwr

                        @marcinozga Thanks, but already tried net.inet.ip.fastforwarding in all combinations with TCP and UDP.

                        1 Reply Last reply Reply Quote 0
                        • 1 / 1
                        • First post
                          Last post