This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Site-to-Site IPSEC Extremely Slow

I have an IPSEC tunnel established between two sites that are within 30ft of each other (the buildings are next door).  Both sites get 100Mbps down / 10 Mbps up.  I setup an IPSEC tunnel between both sites using the default configuration of DefaultHeadOffice and DefaultBranchOffice in the IPSEC settings.  I have policies allowing LAN to VPN and VPN to LAN.  Everything is all pretty basic.

Once I setup the tunnel, I tried to do a simple file transfer of one 20MB file between a branch workstation and a server at Head Office.  It transferred the file at a speed of 0.7Mbps.  Considering both sites get 10Mbps upload, and given some overhead for the VPN tunnel, I would expect the speeds to be at least 7 or 8 Mbps, not 0.7....  Does anyone else have any experiences of insanely slow site-to-site IPSEC tunnels or have any recommendations?

The Head Office has an XG125 and remote office has an XG105 running MR2.  Both are at 50% memory usage and between 0-10% CPU usage.



This thread was automatically locked due to age.
Parents Reply
  • Hi John,

    This command will not work on anything other than a Software, Virtual or XG125 appliance to my knowledge as the other appliances do not have the hardware_acceleration feature.  I think you are best to pursue the RED tunnels, I still have had my fair share of issues with the IPsec VPNs on XG appliances and have had better luck / performance with SSL S2S or RED S2S tunnels.  Disabling PFS is as simple as changing your Phase 2 DH Group to None, I do believe with removing PFS some security will be lost.

    Thanks,
    Hugh

Children