This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

OpenVPN slow transfer speeds

Hello,

SC125, home 125/12mBit, work 50/20mBit. Split tunneling.

The problem seems to arise when I try to transfer more smaller files. Transferring one big file I get almost full speed.

Advanced:

AES-256-CBC

SHA2 256

2048 bit

Local X509 Cert

28800

Compress SSL VPN traffic checked

Any ideas why it's only miserably slow when I transfer smaller files? I checked the CPU usage, it's at about 10%, the firewall is being virtually bored.



This thread was automatically locked due to age.
Parents
  • Hallo,

    Just to confirm - you have an SG 125 at your workplace and you are connecting from your home to the SSL VPN server in the UTM - correct?

    Is it uploads from you PC to a server in the office that are slow, transfers in the other direction or both?  How are you transferring the files - RDP?  FTP? or ???

    The SG 125 doesn't have a very powerful processor, so I would use AES-128-CBC with 1024 bit and I would disable traffic compression.  How much improvement did that get you?

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
  • We have SG125 at work, and I have custom built UTM at home.

    I tried both remote vpn and s2s, with same results.

    The problem mostly manifests when working with smaller files, trying to copy a bunch of smaller files or open a single smaller file. It just takes a lot of time per file. If I zip it and transfer, to start transferring it takes a while,  it after that I get decent speeds.

    I am using SMB, which I know has quite a lot of overhead. I’ll try setting up a FTP connection to test if it works better. And I’ll try lowering the encryption.

  • I just wanted to follow up. Lowering the encryption didn't do anything. The performance with small files over SMB is still miserable.

    But as I really almost never need to copy bunch of smaller files (and I can zip them first), and usually only transfer larger files, I guess I can live with that.

  • Are you using UDP or TCP? If you're using tcp then try change it to udp. There's no reason to encapsulate tcp in tcp

    Sophos UTM 9.3 Certified Engineer
    Sophos UTM 9.3 Certified Architect
    Sophos XG v.15 Certified Engineer
    Sophos XG v.17 Certified Engineer
    Sophos XG v.17 Certified Architect

  • You are right, makes no sense - changed to UDP. I think it might be a tad faster, but not really a wonder (still way faster to zip and transfer). I'll leave it at UDP for now. Thank you.

Reply Children
No Data