cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
415
Views
0
Helpful
5
Replies

Slow VPN Throughput

michael.holroyd
Level 1
Level 1

I have two sites linked with a basic IPSEC tunnel between them.

I am struggling to get any more than 10MB across the VPN.

Site 1 has a 50MB LL and site 2 Is in a Data Centre with a 1GB Max connection.

Both routers are Cisco 1841 routers with VPN cards in.

I understand I will only ever get around 45MB but I am no where near.

I have removed the GRE tunnels and now just a basic IPSEC tunnel.

I have changed from 3DES to DES with no real change.

Any ideas..

5 Replies 5

Philip D'Ath
VIP Alumni
VIP Alumni

Does one site have a PPPoE config, or anything that results in an MTU smaller than 1500?

Have you tried using "ip tcp adjust-mss" with an extreme value, say 1000?  See if that has any impact.

Philip D'Ath
VIP Alumni
VIP Alumni

Do any of the related interfaces have increasing error counters on them?

Can you get the full bandwidth out of the circuit, in both directions, with traffic not going over the VPN?

Philip D'Ath
VIP Alumni
VIP Alumni

ps.  An 1841 wont get even slightly close to 1Gb/s.  It normally only has 100Mb/s ports on it.  How have you interfaced a Gigabit connection to it?

Joseph W. Doherty
Hall of Fame
Hall of Fame

Disclaimer

The Author of this posting offers the information contained within this posting without consideration and with the reader's understanding that there's no implied or expressed suitability or fitness for any purpose. Information provided is for informational purposes only and should not be construed as rendering professional advice of any kind. Usage of this posting's information is solely at reader's own risk.

Liability Disclaimer

In no event shall Author be liable for any damages wha2tsoever (including, without limitation, damages for loss of use, data or profit) arising out of the use or inability to use the posting's information even if Author has been advised of the possibility of such damage.

Posting

As Philip is implying by his post asking about mss-adjust, fragmentation issues will often much slow your router's maximum throughput.  Are you aware of, and have you implemented, a configuration to minimize fragmentation?

michael.holroyd
Level 1
Level 1

Hi,

Both Sites are RJ45 Presentation so no PPPoE to deal with

Both NICs on the 1841 routers have been tried at Auto/Auto and 100/FULL with no difference on the Outside Interfaces.

Have tried with and without "ip tcp adjust-mss 1403" on my external interfaces still no differences.

The ping across the VPN is pretty much ok but does occasionally miss a ping between sites.

Review Cisco Networking for a $25 gift card