I have a IPSec tunnel between two Pfsense machines. Both machines are connected to a 100mbps symmetrical connection. The latency between the two routers is ~70ms. I'm using AES-GCM-128 and SHA1, both machines support hardware acceleration of AES and CPU usage remains < 5%. But I'm having the strangest problem..
Bandwidth peaks around 6MB/s, then gradually decreases to 2MB/s, then gradually increases again to 6MB/s. It's a predictable sine wave. How can I get my bandwidth more consistent?
I tried enabling/disabling compression (currently disabled), playing with the MSS-clamp and MTU settings (1500/1460 respectively) and there doesn't seem to be a difference.
When I download a file directly through the public internet, I get 11MB/s which is closer to my 100mbps max.
What are some things I can try?
0 Answers