ER605 v2 adds SHA2 encryption to the IPsec VPN function and supports IKEv2

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.

ER605 v2 adds SHA2 encryption to the IPsec VPN function and supports IKEv2

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.
23 Reply
Re:ER605 v2 adds SHA2 encryption to the IPsec VPN function and supports IKEv2
2022-11-04 09:39:04

shberge wrote

  @Fae 

 

I do a test with ER605v2 and this router connect to Cisco ASA with no issue with SHA2

 

  @shberge is there any perfomance difference when you use sha1 and sha2?

  0  
  0  
#12
Options
Re:ER605 v2 adds SHA2 encryption to the IPsec VPN function and supports IKEv2
2022-11-04 09:51:23

  @btx 

 

No speed is the same, starting pretty good at 200Mbps and go fast down to 50-60 Mbps.

 

 

 

 

  0  
  0  
#13
Options
Re:ER605 v2 adds SHA2 encryption to the IPsec VPN function and supports IKEv2
2022-11-04 09:55:07

  @shberge thanks for the info. Also, how do you mean it goes quickly to 50-60? When you run iperf, does it start with 200 and goes slowly down or do I missunderstand it? 

  0  
  0  
#14
Options
Re:ER605 v2 adds SHA2 encryption to the IPsec VPN function and supports IKEv2
2022-11-04 09:59:52

  @btx 

 

I copy a file, it starts with about 200Mbps and quickly drops to 50-60Mbps when I copy. if I do the same on Cisco firewalls, the copying is stable all the time if it starts at 300Mbps then it stays at 300Mbps until the copying is finished

 

  0  
  0  
#15
Options
Re:ER605 v2 adds SHA2 encryption to the IPsec VPN function and supports IKEv2
2022-11-04 10:08:15

  @shberge interesting, when it drops to 50, is routers cpu usage high/max? In standalone mode htop is availabke (system monitor) over ssh, not sure it works if afapted, but if it works, there you could see if hw hits its limits, sometimes spikes are caused by bugs too, thats why I was curious about speed drop.

  0  
  0  
#16
Options
Re:ER605 v2 adds SHA2 encryption to the IPsec VPN function and supports IKEv2
2022-11-04 10:19:21

  @btx 

 

I think it's a combination of lots of bugs and weak hardware, I'm excited about the new ER8411, how is the VPN on this one? I ordered one but it hasn't arrived yet.

  0  
  0  
#17
Options
Re:ER605 v2 adds SHA2 encryption to the IPsec VPN function and supports IKEv2
2022-11-04 10:40:50

  @shberge vpn on er8411 should give you above 1Gbit, which is quite good, however, it is a good question what quality of its firwmare is, if it is as buggy as other business series, then performance would go down. ER8411 is excellent device on paper, like omada and whole business line, sadly reality looks different, one can be happy if it just works, even with performance issues. I strugle at the same to recommend tplinks business line, to be more specific, I do not recommend omada, standalone mode is more stable and network does not break by controller bugs, but I still do not recommend unstable device to be a gateway.

 

I do not have v2 of er605, I was duped by tplink and was sold v1 which is last device I bought from tplink. I have no clue which bins are in v2 firmware, if you run ls /bin, ls /usr/bin as well as busybox help, available bins/commands would be listed. When you start system monitor, it lists every process and its cpu/ram usage. That way you actually can see where cpu and ram is used.

 

To me the drop looks like performance issue from description which I read, I would expect v2 to be able to handle 200Mbit, seems v2 is even more buggy than v1.

  0  
  0  
#18
Options
Re:ER605 v2 adds SHA2 encryption to the IPsec VPN function and supports IKEv2
2022-11-04 14:28:46

  @btx 

I use tp-link mostly for fun, besides, I like the concept and there is great potential for preparation. so I use TP-Link private at home and my children's houses and a lab at work, but I probably wouldn't have recommended tp-link routers to my worst customer, I'm not that bad :-) but in two years they might have something good , it's gotten a little better with each update thankfully, but they still hold the world record for buggy firmware I think :-)

 

  0  
  0  
#19
Options
Re:ER605 v2 adds SHA2 encryption to the IPsec VPN function and supports IKEv2
2022-11-04 14:39:46 - last edited 2022-11-04 14:41:00

  @shberge its fully ok as long as you are aware of the backdrops, which you for sure are. I wrote it because 10/10 requests to help fix broken network came from people who were not aware of issues and trusted tplink, my first omada gear was when one of those 10 brought his $ 3000 equipment and gifted it in saying you take it or it lands in trash, I cant even sell this **** to anybody. Thats in general the feedback which I received, only one of 10 has kept its tplink gear at the end as it costed more to fix network issues than buying new decent hw. Beside all of that, I supported and distributed tplinks products for decades, mostly with openwrt for home use and those devices still work, back then it was better alternative to linksys devices like wrt54gl.

  2  
  2  
#20
Options
Re:ER605 v2 adds SHA2 encryption to the IPsec VPN function and supports IKEv2
2023-01-07 12:17:10

  @Fae This still doesn't work in January 2023. Your last firmware update was alsomost a year ago. I went out of my way to buy the v2 of ER605 because I need SHA2, just to find out that it still doesn't work, because I am being a good digital citizen and keeping my controller software up-to-date.

 

Come on guys, is this is a joke or something? When do you plan to make this work?

 

Thanks in advance!

  0  
  0  
#21
Options