PDA

View Full Version : VPN traffic severely de-prioritized?


anduin
19-02-2007, 19:28
Did anybody else notice that for the last 3 months or so VPN traffic seems to have been massively de-prioritized ?

i used to be able to rsync in about 10 mins, however now it can take upto 3 hours ( not to mention disconnects etc )

example speedtest when connected through vpn::

https://www.cableforum.co.uk/images/local/2007/02/68.png (http://www.speedtest.net)

martin42h
19-02-2007, 19:35
I have no problems with VPN speeds connecting with my company's server (in Germany).
I should talk to the VPN destination network admin, problem likely there.

anduin
19-02-2007, 19:40
I am the vpn server admin, and on any other connection its fine but not on ntl :)

It was actually perfect some 4 months ago - i was pulling every last drop from the adsl connection where the vpn server sits. Then one day it decided to go slow, and has remained the same since.

JonathanLH
19-02-2007, 20:02
if the vpn server runs on an adsl line, how fast did you expect it to go? since the speedtest above is correct for a 512/128 cheap adsl line

Carl J
19-02-2007, 21:47
if the vpn server runs on an adsl line, how fast did you expect it to go? since the speedtest above is correct for a 512/128 cheap adsl line

Minor issue that there is no such thing as a 128kbps upload ADSL service in the UK, and for all you know OP may have the server hosted on SHDSL, 2Mbit symettrical or higher. Please do note he mentions that non-ntl connections see better performance.

anduin, try adjusting the MTU on your network card to say 1400, you may be having issues due to the extra overhead placed on the packets causing them to be fragmented by the VM network in transit which can break VPNs.

Wicked_and_Crazy
19-02-2007, 21:50
never have VPN issues here

anduin
19-02-2007, 22:13
@ CarlJ ... thanks will give that a try now

and @ JonathanLH ... We use MaxDSL and sync at 4.5mb/832kb

and i expect to see about 700kb of that :D

rikur
19-02-2007, 22:38
I actually get slightly the opposite....

I have a VPN running between my house in London and Manchester, and have network testing running every hour between the two, both via the VPN, and directly to an unencrypted TCP port

the 3 month average through the VPN tunnel is 54.748ms, whereas outside the VPN it is 99.467ms.

I would expect the VPN tests to be slower because of the IP-SEC overheads - both from a firewall processing latency and bandwidth usage, but they're not.

I've never really understood the results, but it has stayed pretty consistent over many months. I've asked a few Cisco qualified colleagues, and they have no idea either, suggesting it is either a quirk of the ntl network, or possibly the way the firewalls at each end handle things like NAT/PAT and out-of-sequence packets.

I use Unison to sync between the two sites (better than RSync for bidirectional syncing) and it sites quite happily at 370kbps each night, which is more or less equal to 400kbps uplink minus IP SEC overheads)

The Jackal
21-02-2007, 11:40
I use Unison to sync between the two sites (better than RSync for bidirectional syncing) and it sites quite happily at 370kbps each night, which is more or less equal to 400kbps uplink minus IP SEC overheads)

Unison ! LOL ! You have got to be kidding me - right ? Please read the rsync manpage it's not THAT complicated !

To OP... You can rsync over ssh too and do away with the VPN.

As I have mentioned previously I sync up many many gigs a day over my 2meg connection