Quantcast
Channel: EdgeRouter topics
Viewing all articles
Browse latest Browse all 20028

Site-To-Site IPSec VPN tcp connection latency

$
0
0

I have two ERX in two sites using a VTI IPSec site-to-site VPN.  The VPN works well, pinging between computers on opposite sites are fine too (consistently ~40-50ms).

 

But if I use SSH over the the tunnel (ie, ssh to a remote computer, or to the remote ERX), it feels very sluggish - it takes a second or more for a keystoke to register.  It's almost like a tcp_nodelay or Nagle's algorithm related, but I'm not sure

 

Things I've tried so far without success.

  • Removing QoS on both ends
  • Disabling hwnat offload
  • Disableing ipsec offload
  • Reducing IPSec / IKE strength.

 

Currently running 1.9.1beta1, but I saw this in 1.9.0.

 

Has anyone seen this?


Viewing all articles
Browse latest Browse all 20028

Latest Images

Trending Articles



Latest Images

<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>