Orbi WiFi 7 RBE973
Reply

VPN Performance

OCS781
Aspirant

VPN Performance

I have 3 sites connected to each other using IPSEC VPN with 3 FVS336Gv3 firewalls.

 

I am trying to troubleshoot reports of slow traffic between 2 of the sites (SITE A and SITE B), the 3rd site uses very little bandwidth.

 

The broadband service at SITE A is 10mbs synchronous and SITE B is 20mbs synchronous.

 

SITE A is where the complaints are coming from. I do not administrate the LAN on SITE A but documentation suggests there are 50 users made up of a few servers, medical machines and workstations.

 

Both SITE A and SITE B make use of 10 or so port forwarding rules that are handled by the firewalls.

 

The system administrators have suggested that the Netgear firewalls are not able to handle the throughput. 

 

According to the Datasheet the VPN throughput is 78mbs which exceeds the broadband service provided, I suspect that the service may be choking

due to general internet usage on the site by employees. The internet usage is not regulated.

 

Is there a practical way to prove this? am I correct in assuring that the FVS336Gv3 hardware is capable of handling the 'load'?

 

Thanks for the help.

Model: FVS336Gv3|ProSafe dual WAN gigabit firewall with SSL and IPSec VPN
Message 1 of 7
DaneA
NETGEAR Employee Retired

Re: VPN Performance

Hi OCS781,

 

Welcome to the community! 🙂 

 

Kindly try to lower down the MTU size on all FVS336Gv3.  Refer to the table below as reference:

 

 

What is the current firmware version of all FVS336Gv3? 

 

 

Regards,

 

DaneA

NETGEAR Community Team

Message 2 of 7
OCS781
Aspirant

Re: VPN Performance

Thanks for the tip

 

firmware is 4.3.3-6

 

I will try the MTU settings.

Message 3 of 7
DaneA
NETGEAR Employee Retired

Re: VPN Performance

@OCS781,

 

I just want to follow-up on this.  Were you able to try to change the MTU settings of the FVS336Gv3 firewall routers?  If yes, what are your observations?

 

Also, let me inform you that firmware version 4.3.5-3 has been recently released for the FVS336Gv3.  If ever you wanted to upgrade the firmware of all the FVS336Gv3 you have, you can download it here.  Be reminded to perform a factory reset on the FVS336Gv3 after upgrading the firmware then reconfigure it from scratch in order to start clean using the latest firmware version.

 

 

Regards,

 

DaneA

NETGEAR Community Team 

Message 4 of 7
OCS781
Aspirant

Re: VPN Performance

The client has decided to go with a UTM type device to secure the network and limit internet usage,

 

unfortunately they are using a different company to implement the solution.

 

Thanks for the assistance anyway.

Message 5 of 7
OCS781
Aspirant

Re: VPN Performance

Hi,

 

Just an update. I managed to adjust the MTU size to 1436 and the VPN performance has improved.

 

The site will be upgraded to a faster internet speed (20mbs) so I will monitor after the change.

 

 

Thanks.

 

Gary.

Message 6 of 7
DaneA
NETGEAR Employee Retired

Re: VPN Performance

@OCS781,

 

Thanks for the update.  I'm glad to know that the VPN performance has improved after changing the MTU size to 1436. 🙂 

 

Keep us posted.

 

 

Regards,

 

DaneA

NETGEAR Community Team

Message 7 of 7
Top Contributors
Discussion stats
  • 6 replies
  • 4990 views
  • 0 kudos
  • 2 in conversation
Announcements