I have a dedicated virtual machine for OpenVPN UDP site-to-site connections behind an UTM.
If I connect the VM using NAT through the UTM (DNAT for the OpenVPN port to the VM's RFC1918 address and SNAT back out), I have consistently 5-15% packet loss in the tunnel.
If I connect the VM using an external IP routed through the UTM, the packet loss is gone.
CPU load on the UTM never exceeds 25%. Firewall logs show nothing interesting.
Ideas?
This thread was automatically locked due to age.