Poor speed on ER605 site2site VPN

Poor speed on ER605 site2site VPN

Poor speed on ER605 site2site VPN
Poor speed on ER605 site2site VPN
Yesterday
Tags: #VPN #ipsec
Model: ER605 (TL-R605)  
Hardware Version: V2
Firmware Version: 2.2.4 Build 20240119 Rel.44368

Hi, I've set up a IPsec site to site VPN from my ER605v2 to a Meraki Z4.

 

ER605 side - 1Gbps service
Meraki Z4 side - 500 service

 

This is what I see for ER605v2 specs from this post: https://community.tp-link.com/en/business/forum/topic/709696

r/TpLink - ER605 site to site VPN speeds? Your throughput??

 

Althogh originally not the case, I've made changes so the site to site VPN uses ESP-SHA1/SHA256-AES256 but most I can get is 40Mbps, TOPS.

 

My settings

r/TpLink - ER605 site to site VPN speeds? Your throughput??

and

r/TpLink - ER605 site to site VPN speeds? Your throughput??

 

I assumed my site to site speed would improve, but noting, still max 40Mbps; tested with iperf3

.

The Meraki Z4 is capable

 

Stateful Firewall Throughput 500 Mbps
Maximum VPN Throughput 250 Mbps
Security Throughput 500 Mbps

 

Not sure what else I can try here, and not sure what is the issue.

 

Is anyone getting close to those 200MBps+ speeds on an IPsec site2site VPN on the ER605, as in that tablre??

 

TY

  0      
  0      
#1
Options
3 Reply
Re:Poor speed on ER605 site2site VPN
16 hours ago - last edited 16 hours ago

  @words try AES-128 instead of AES-256, you'll get some more speed.

 

I have an IPSEC Tunnel in AES-128 against one Fortinet and I could reach about 150 Mbps.

 

 

EDIT: I'm using IKEv1 not IKEv2

  1  
  1  
#2
Options
Re:Poor speed on ER605 site2site VPN
13 hours ago - last edited 13 hours ago

  @words 

the router can handle 200-250Mbps with IPsec, 
use encryption like this for best performance

 

 

If you don't get 200Mbps or more, you need to look at your Cisco router.

 

 

here is my speed when copying a file to an ER605 router via Omada SD-WAN. it is about the same speed as Ipsec site to site

 

 

  1  
  1  
#3
Options
Re:Poor speed on ER605 site2site VPN
9 hours ago

Ok, thanks for the feedback, apparently my testing method has been wrong.

Using iperf3 sends a single thread, so it's only indicative of that, as I added more threads to iperf3 I bigger bandwidth.

I also changed to AES128 as suggested then tried a 1Gb file transfer.

My speed on the file transfer hit 300Mbps at some points, but overall during the transfer the speed ramped up to around ~260/280Mbps so looks like all is well.

 

Thanks for all the responses, this helped me get it done!

Cheers

  1  
  1  
#4
Options