DrayTek UK Users' Community Forum

Help, Advice and Solutions from DrayTek Users

Slow L2TP VPN between 2865 & 2860

More
09 Dec 2021 13:17 #1 by pharcyder
Slow L2TP VPN between 2865 & 2860 was created by pharcyder
Hi all,

For quite a while I've had an L2TP/IPsec tunnel running between a 2865ac and a 2860. The 2865 is connected to a symmetrical gigabit FTTP connection, the 2860 connected to a vDSL connection which synced at 40/9. We use the link to perform rsyncs of data overnight from the 2865 to the 2860 and I would get roughly 4MB/s throughput as one would expect to see.

Site 2 upgraded their vDSL connection to a 100/20 FTTP service with Zen. The 2860's WAN1 was disconnected from the VDSL service and WAN2 was connected to the OpenReach ONT.

The same L2TP/IPSec tunnel establishes correctly however now the speed has dropped to 15-20Mb/s halving the throughput I saw before. All Bandwidth management features are disabled both ends. Speedtests for clients on the Zen connection max out the 100/20 link so the bandwidth is there. Hardware acceleration doesn't seem to make any positive difference on the 2860, neither does disabling its FW.

I'm using iperf3 in both direction to measure the speed over the tunnel. I am at a complete loss was to why there is a speed difference between WAN1 connected to a VDSL connection and WAN2 connected via ethernet to an ONT which is over twice the speed in both directions. Its such be twice as fast, not twice as slow.

Any ideas?

Edit: Tried switching to a IKEv2 VPN, sadly same throughput challenge

Please Log in or Create an account to join the conversation.

  • hornbyp
  • User
  • User
More
21 Dec 2021 18:00 #2 by hornbyp
Replied by hornbyp on topic Re: Slow L2TP VPN between 2865 & 2860
I've only just noticed this ...

pharcyder wrote:
The 2860's WAN1 was disconnected from the VDSL service and WAN2 was connected to the OpenReach ONT.



Did you also disable the 2860's WAN1 connection? I believe this can have an impact ... maybe it's trying to load-balance?

Please Log in or Create an account to join the conversation.

More
21 Dec 2021 18:03 #3 by pharcyder
Replied by pharcyder on topic Re: Slow L2TP VPN between 2865 & 2860
It has been, yeah. I was aware of the same issue. Just can't work out where the bottleneck is.

Please Log in or Create an account to join the conversation.