OPNsense Forum

Archive => 18.1 Legacy Series => Topic started by: c-mu on July 06, 2018, 01:47:42 pm

Title: IPSec 100MBit limit?!
Post by: c-mu on July 06, 2018, 01:47:42 pm
Hi,
i just bought an Decisco OPNsense Dual A10 DC rack Appliancen and configured a IPSec Tunnel for testing purposes. So I connected the WAN interfaces directly and both are showing a 1000baste T <full duplex> Status at the Interface Overview.

So if I do some speed tests like iperf or downloading an big ISO file between the VPN Sites via wget, I allways got limited by 100MBit/s. What causes  that hard limit? Not 110, not 120, not 90 Mbit, every Time and test is allways limited by 100MBits. The WAN interfaces should deliver 1GBit. I woulnd expect 1GBit IPSec speed, but something round about 200MBit should be possible.

I'm confused.
PS: i played around with some other encyption algorithm from weak to strong - nothing has any impact on the speed.

Thanks for any hint!
Title: Re: IPSec 100MBit limit?!
Post by: mimugmail on July 06, 2018, 01:56:48 pm
AES128GCM, SHA256, DH14 .. normally should give you way more.
Sure there's no Traffic Shaper? Can you test without VPN?
Title: Re: IPSec 100MBit limit?!
Post by: c-mu on July 06, 2018, 02:03:17 pm
Yip. There is no traffic sharper. its nearly a default setup. I changed the the settings to AES (128bit) + SHA256 +DH G14 and its not slower or faster than before.
Title: Re: IPSec 100MBit limit?!
Post by: mimugmail on July 06, 2018, 02:09:22 pm
And plain?
Title: Re: IPSec 100MBit limit?!
Post by: c-mu on July 06, 2018, 02:26:35 pm
You mean DH Key group "off"? changes nothing. there's a freaky 100 mbit wall, that i cant break through. I even attached a 1gbit switch and the status led's shows a 1gbit connection too.
Title: Re: IPSec 100MBit limit?!
Post by: mimugmail on July 06, 2018, 03:20:43 pm
 I mean plaintext download without ipsec