03-27-2019 05:36 PM
I have setup a DMVPN network over a ISP MPLS network.
And I have conduct file transfer test from one end to the other end though the DMVPN network, and find that the thoughput is 80% of the link bandwidth (e.g the link bandwidth is 10Mbps but the actual thoughput is arpund 8Mbps)
My setup on the IPSec is ESP-AES with ESP-SHA-Hmac and on the tunnel,
Mtu size 1400 and ip tcp adjust mss is 1360 according to thw best pratice from Cisco.
Is there any way to fine tune my parameter to enhance the thoughput to reach 10Mbps?
03-27-2019 05:39 PM - edited 03-27-2019 05:42 PM
what kind of device in the network, what is the IOS Code you running on them
show can you provide show version, and show running config .
Important check the CEF config on tunnel interface.
03-27-2019 08:18 PM
Hi,
Can you share some more information as Hardware details, IOS details, Both end Internet connection Bandwidth, Delay between your ISP (Check online) and other Internet uses and CEF status?
Second, As you are getting 80% throughout of your total bandwidth so I am not looking any issue with configuration or etc. Of course, you will not 100% throughput over the VPN because of VPN is also an overlay communication. Somehow it will depend on the underlying network.
Regards,
Deepak Kumar
03-28-2019 12:02 AM
Hello,
on a side note, you could try and configure tunnel path mtu discovery on your tunnel interfaces:
interface Tunnel0
tunnel path-mtu-discovery
Also, depending on your tunnel configuration, if you use mode transport, that will slightly decrease the MSS payload (not sure if that makes much of a difference when it comes to throughput in your case):
crypto ipsec transform-set TS esp-aes 192 esp-sha-hmac
mode transport
03-28-2019 06:21 AM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide