This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

slow vpn traffic through utm


utm version is 9.707-5

I use the utm for routing and network security on my home network.

I have a subscription to a vpn service provider. The vpn protocol is openvpn (over udp). When I start the vpn service's client on my macbook and enable the vpn, my connection speed drops from about 300Mbps to about 1Mbps. The vpn service works fine -- near the speed of the network -- at all locations away from my home. So, I suspect I have something configured wrong on the utm.

I created a firewall rule to do some testing that permits any type of ip traffic from my internal/inside interface to any other interface and have logging enabled for the rule. The rule is in the topmost position. When I open the live log view for the firewall log I see all of the traffic from my macbook with the vpn client disabled. When I enable the vpn client, all traffic from my macbook disappears completely from the log. Not a trace of the macbook's network activity. The macbook is getting external network access. I can load websites just very, very slowly.

So, my question is sort of twofold:

1.) Any ideas as to what might be causing the vpn network traffic to traverse the utm so slowly? Why would openvpn over udp packets be treated differently than any other udp packet?

2.) How can I see the vpn traffic in the firewall log? My hope is that there might be some clues as to what's happening here in that log file. It is a place to start anyway.

I did try some general searching already but any search that includes the terms 'vpn' and 'utm' mostly returns results related to setting up the utm to be a vpn endpoint or to configuring vpn tunnels on utm. That's not what I'm trying to do. I just want my openvpn traffic to traverse the utm with the same speed as for all my other IP/UDP traffic.

Thank you for any ideas, thoughts, suggestions.



This thread was automatically locked due to age.
Parents
  • Hello,

    sounds like a MTU size problem, maybe you try that at your endpoint device. Try 1300 bytes as a starting point.

    Mit freundlichem Gruß, best regards from Germany,

    Philipp Rusch

    New Vision GmbH, Germany
    Sophos Silver-Partner

    If a post solves your question please use the 'Verify Answer' button.

Reply
  • Hello,

    sounds like a MTU size problem, maybe you try that at your endpoint device. Try 1300 bytes as a starting point.

    Mit freundlichem Gruß, best regards from Germany,

    Philipp Rusch

    New Vision GmbH, Germany
    Sophos Silver-Partner

    If a post solves your question please use the 'Verify Answer' button.

Children
No Data