PPTP , IPSEC/L2TP performance

From: Roy Sanders (royss_at_sci.kun.nl)
Date: 08/21/03


Date: 21 Aug 2003 02:41:46 -0700

hi,

I'm working on a project with VPN's.
I've succesfully set up a PPTP server and a IPSEC/L2TP server with
PKI.
As this all seemed to work, i did a little performance test.
When i downloaded via the LAN it would go around 1,7 Mb/s with 1
client.
When i tried with multiple clients from outside the LAN the
performance is somewhat crap. i can get about 300-400 kb/s out of the
box and that is about it.
both with IPSEC/L2TP and PPTP seem to have this problem.
The server that i used isn't that fast its only a PII 350Mhz.
The WAN connection to the internet is a 100 Mbit surfnet connection.
The clients i used to test from outside the LAN should be able to
download faster.
I tuned the MTU a bit but not really a difference. its about 1410 now.
My ifconfig says that the MTU of the pppX interface is 1406.

Q:Why is the performance from outside the LAN so much worse ?

Q:tcpdump tells me the kernel drops about 1/5 of the packets when
there is a lot of traffic comming tru.

Q: Could it be the machine that isn't capable of creating GRE packets
fast enough to multiple client ?

Q: is this a kernel restiction with /dev/pts ?

Any comments/advices are appreciated.

-- Roy Sanders



Relevant Pages

  • Re: smbclient timeout, file truncated / 9.1 Pro (was Re: libpopt.so.0 conflict...
    ... >and the OS/2 machines on the LAN. ... NETBEUI was invented to allow windows clients to use an OS/2 server. ... 9 buffer small read and write requests until the buffer is full ... Acknowledgment Timeout ...
    (alt.os.linux.suse)
  • Re: Indirect synchronization setup with no synchronizers on servers
    ... Replica Manager to be installed at all. ... trust any LAN, except the LAN where the file server is that stores my ... remote PCs have synchronizers but the server does not. ... There is no difference between a synchronizer operating on replicas ...
    (microsoft.public.access.replication)
  • Re: Possible to secure WEP?
    ... It doesn't have to be a "server". ... this IP cannot be in the same class C IP block as your own LAN. ... To keep it simple, my gateway router, ... Ethernet adapter Local Area Connection: ...
    (alt.internet.wireless)
  • Re: Can only connect to local RWW, over internet cannot
    ... OK, so now we know RWW works, and it is a function within RWW, the ability ... to 'Connect to Server' which is problematic, from inside the LAN. ... The 'Connect to server desktops' and 'Connect to my computer at work' ... RDP Proxy dynamically opens the connection to the requesting IP so at this ...
    (microsoft.public.windows.server.sbs)
  • Re: VPN: Can connect but not browse or do anything
    ... With a workgroup, you have 2 master browser on 2 segments, and no way ... If you setup a domain, I'd recommend a DNS server, as WINS is legacy technique. ... all connected in a LAN behind a router. ... We need to share these 3 printers with the ...
    (microsoft.public.windowsxp.network_web)

Loading