Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Slow site to site IPsec VPNs

Hello.  I have an issue where we have 9 remote sites connecting via Site-to-Site IPsec VPN and are very slow.  These remote sites are running Pepwave Max BR1s and are configured using AES-256, MD5, Group 5 and are on Charter cable modems.  When I hook directly up to the cable modem and go out I'm get 60/4, but 3/.5 when connected via the tunnel. Our UTM is a Sophos SG310 and is sitting on a 100/100 connection, which we were told would handle the amount of remote sites easily.  I've checked, and our speed is no where near the 100/100 at any time during the day.  Is there something else I should be checking?



This thread was automatically locked due to age.
Parents
  • Hi, and welcome to the UTM Community!

    Does doing #1 in Rulz give you any clues?

    If not, you might have the MTU issue.  Does the Interface definition indicate an MTU of 576?

    Cheers - Bob

  • Per your suggestion, and the suggestion of Sophos, I disabled IPS and tested it.  There was very little improvement.  I had support remote into my machine and do some troubleshooting.  The only things that he could come up with was that this is normal (9MB downloads from a charter 60/4 connection to a 100/100 connection), then he said that our 100/100 isn't enough to handle the amount of tunnels that we have (even though we're only using about 30MB of it), and that I should enable compression for all of the tunnels.

    Also per Rule #7, bullet #3, I lowered the MTU from 1500 to 1350 on the external connection.

    I guess I don't agree with the tech's answer, because I can hook a RED up to the device (without an IPsec tunnel up) and get 55/4 speeds through speedtest.  So, in my mind, there has to be something wrong with the IPsec, or the way that it flows through the UTM.

  • My suggestion wasn't to disable IPS, it was to examine the logs.  If you re-read #1, you might realize that disabling IPS makes no difference.  I doubt that lowering the MTU helps the problem you're having.  What do you see in the logs?

    Cheers - Bob

Reply
  • My suggestion wasn't to disable IPS, it was to examine the logs.  If you re-read #1, you might realize that disabling IPS makes no difference.  I doubt that lowering the MTU helps the problem you're having.  What do you see in the logs?

    Cheers - Bob

Children