Quantcast
Viewing all articles
Browse latest Browse all 60861

Re: OpenVPN site-to-site tunnel - ERLite to ERLite - best vpn throughput settings?

I'm pretty sure OpenVPN is not hardware accelerated on an ERL or ER-X.

 

IPSec can be, if you enable it and use the correct settings.  The trick to making IPSec work is to make absolutely 100% sure that everything matches up correctly on both sides.  That's the cause of 99% of ipsec failures to connect that I've ever seen.

 

Additionally, when you're comparing network speed, talk in megabits.  Sure, Windows reports in megabytes, but basically zero network equipment ever references bytes except as a convenience on reporting pages.

 

I just passed ~250Mbps (using iperf) over an IPSec tunnel between an ER-X and a Palo Alto 3050... and that was with iperf running on the ER-X itself, not on a separate PC behind the ER-X (which is most likely why it was as slow as it was).  The physical link between the two is gigabit, this was a proof of concept test...

 

Using IPsec with the hardware offload enabled on both sides of a ERL-ERL tunnel, you should be able to keep up with almost any WAN link you throw at it.

 


Viewing all articles
Browse latest Browse all 60861

Trending Articles