Re: Help on home setup
Thank you! I will do that when I get home. There isnt possible to do this from the gui?
View ArticleRe: change open vpn to tcp 443
Your changes will work....I have identical config lines. First alter gui listen address or port though
View ArticleRe: Help on home setup
Indeed on faster links you're better off without QoS, and use offload to get max bandwidth combined with low CPU On slower links, no offload and QoS is the best. Question remains: at what speed do we...
View ArticleRe: Firewall policies not working.
You should apply WAN_IN in direction inand WAN_LOCAL in direction local. (this 2nd step will stop exposing the ER) Best explanation...
View ArticleRe: Traffic Analysis on ER Pro
I don't believe this is possible on the ER's, you can either run tcpdump or a packet capture via CLI or setup netflow and then use a flow analyzer such as scrutinizer or PRTG. The traffic analysis on...
View ArticleRe: IPSec Site-To-Site extremely low throughput VTI
goldlineIT wrote:how about changing 3des to aes128Unfortunatly that also had no effect, my gut tells me its an MTU issue because CPU isn't pinned or anything but I don't even know where to start with...
View ArticleRe: IPSec Site-To-Site extremely low throughput VTI
I just did a traceroute and that's making me think maybe it's a routing issue?
View ArticleRe: IPSec Site-To-Site extremely low throughput VTI
I think you might be right, add ospf rules
View ArticleRe: How do you Upgrade X SFP to 1.9.1 ?
Check sudo du -sh /root.dev/w/* and repeat for the larger folder you'll see there ...drill down until you find the problem ...report back pls, I'm curious what consumes the size.
View ArticleRe: IPSec Site-To-Site extremely low throughput VTI
I made sure my static routes were working right with the VTI and the traceroute now is showing the IP of the vti0..but times are still horrible. I'll try to get OSPF setup and see what that does, but...
View ArticleRe: IPSec Site-To-Site extremely low throughput VTI
set protocols ospf parameters router-id [WAN] set protocols ospf area 0.0.0.0 network 40.0.0.0/30 set protocols ospf area 0.0.0.0 network 192.168.1.0/24 set protocols ospf area 0.0.0.0 network...
View ArticleRe: IPSec Site-To-Site extremely low throughput VTI
i need to see your static routes, you should have deleted the default and only have 1 per router pointing to the next router via vti0
View ArticleRe: IPSec Site-To-Site extremely low throughput VTI
no im wrong you can delete all static routes ospf should handle everything
View ArticleRe: IPSec Site-To-Site extremely low throughput VTI
Okay..so I added the OSPF routes and deleted the static routes and my traceroutes are looking the same with the same long latency, I'm running a reboot on both ends right now just to make sure the...
View ArticleRe: IPSec Site-To-Site extremely low throughput VTI
Im slowly going through the config sorry.enable nat-traversal
View ArticleRe: IPSec Site-To-Site extremely low throughput VTI
also set ipsec interfaces and nat networks (nat networks allowed can be 0.0.0.0/0) under ipsec settings
View ArticleRe: IPSec Site-To-Site extremely low throughput VTI
goldlineIT wrote:Im slowly going through the config sorry.No problem, thank you so much for helping!! goldlineIT wrote:enable nat-traversalThat didn't do it After each change I'm running an iperf,...
View Article