Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

OpenVPN SSL slow over the pond

Hey People.

 

It's great to have a good community here.

Hopefully you can help me this time?

 

We are facing really weird issues related to bandwidth over OpenVPN.

 

We have 1Gbit upload. It seems that the more latency the connected client has, the more the bandwidth suffers.

We tried different setting of encryption, no change. We have CPU load on the UTM always ~10-20%...

 

If it goes well I'm getting 1-1,5MB/s (MegaByte)...but often it's stuck at ~2-400 KB...

I added IPS exceptions, checked packetfilter and ips logs. There's nothing being dropped or so!

 

Any idea what this could be?

 

Cheers

David



This thread was automatically locked due to age.
  • Hi Sachin,

     

    the latency seems quite normal to me, given that it was from Switzerland to US west coast...

     

    From Germany to the Swiss office I have this:

    --- XXX ping statistics ---
    103 packets transmitted, 103 received, 0% packet loss, time 102135ms
    rtt min/avg/max/mdev = 52.607/54.137/58.961/1.120 ms

     

    I don't want to change to SHA1, as it's not safe.

    The current settings are:

    Encryption Algorithm: AES-256-CBC

    Authentication Algorithm: SHA2 512

    Protocol:UDP

    Compression disabled

    Key size: 4096

     

    In the past we had:

    Encryption Algorithm: AES-128-CBC

    Authentication Algorithm: SHA1

    Protocol:UDP

    Remove compression

    Key size: 1024

     

    But it was just the same...