DrayTek UK Users' Community Forum

Help, Advice and Solutions from DrayTek Users

2766ac performance unusable for AnyConnect VPN

  • horace
  • Topic Author
  • Offline
  • New Member
  • New Member
More
09 Feb 2022 16:47 #1 by horace
Hi, hoping someone can help me please?
I've been using the 2766 for a while now and all appears to work OK for all uses except my work laptop, that uses AnyConnect VPN for the connection back to the office. On my standard devices I get the full network speed expected. On my work device I get network quality issues with all of the below and it is worse if more than one is occurring at the same time:
  • Teams calls

  • File copy over VPN using Explorer but not with PowerShell

  • Drops in Dameware remote sessions

I've tried a couple of laptops, reloaded from scratch and compared with colleagues devices.
The 2766 has been updated to the latest firmware. Work laptop is patched to the hilt and has been updated through the Windows versions and none have made a difference either way.

All the testing above resulted in my turning my Virgin box back to router mode and testing again. Using the virgin hub3 in router mode the problems go away.

Can anyone recommend where to start to investigate this further please as it is clear either the 2766 or the config for the 2766 is the cause of the issue.
I was going to look at QOS but that requires hardware acceleration enabling and when I do that I get a warning that DDOS will be partially impacted.

I really don't want to have to resort to putting the Draytek kit in the loft space and configuring the Virgin hub to router mode, so any assistance would be really gratefully received.

Thanks

Please Log in or Create an account to join the conversation.

More
10 Feb 2022 00:21 #2 by edinburgh
What's your firewall settings, in particular UDP?

Please Log in or Create an account to join the conversation.

More
10 Feb 2022 10:10 #3 by admin3
What's the DDOS warning it gives when enabling hardware acceleration?

Since whatever's happening is causing issues even with fairly low bandwidth streams, I suggest looking at the WAN2 settings first since you say it's connected to a VM router.
The default MTU on the DrayTek looks like it's 1492, but the VM network should support 1500. You could use the Path MTU discovery to verify the right MTU for that WAN.
It might be worth turning off the "Change the TTL value" setting as that shouldn't be needed with the VM network.

Watch the router's CPU usage on the Dashboard to see if maybe it spikes along with your connection issues, maybe there's some underlying problem.
I recommend turning on Hardware Acceleration though what you're seeing shouldn't really be happening with it on or off. To get the best out of hardware acceleration for WAN2, disable WAN1 in WAN > General Setup.

It's not clear whether you're using wireless or wired connection, try wired if using wireless to see if that helps.



Forum Administrator

Please Log in or Create an account to join the conversation.

  • horace
  • Topic Author
  • Offline
  • New Member
  • New Member
More
28 Mar 2022 19:26 #4 by horace
Apologies, I've not been able to respond to the offered help sooner.

  • Regarding the firewall, I've a lot to learn on this but so pretty much standard out the box with max paranoia settings applied. Just noticed that UDP Flood Defence may impact UDP services so increased threshold in line with BB speed.

  • DOS warning when enabling hardware acceleration is 'Enabling HA will cause DoS Defence to work partially. Packets that have been accelerated by HA will not be checked by the DoS Defence function.'

  • I wasn't sure if the improvement from HA would be worth the loss of function in DoS Defence.

  • MTU discovered to be 1492 so left at that.

  • Turned off Change the TTL value

  • WAN1 already disabled.


I know I've changed a few things at once here but if there is any change I can regress to see which setting(s) made the difference.
I can also look at the CPU as advised.

User both wired and wireless, no change between the two so looks like the issue is between the router and the VM box.

Thanks for your help.

Please Log in or Create an account to join the conversation.