Trying to improve the speed of a site to site connection from a clients office network to their server in our data center. Both the on-site and cloud units are fully licensed. Would switching them over to IPsec give any better performance?
Announcement
Collapse
No announcement yet.
Is an Untangle/Arista IPsec VPN faster then a site to site OpenVPN connection?
Collapse
X
-
The speed of a VPN link generally has more to do with the quality of the ISP on both ends and ability of the end-user hardware to offload the routing to the network chip rather than do it in the CPU. The specific VPN technology used is the least important factor.Five time Microsoft ASP.Net MVP managing a Lenovo RD330 / E5-2420 / 16GB with Untangle 16.5.2 to protect a 1Gbps fiber link for ~450 residential college students and associated staff and faculty
-
Originally posted by djrees View PostWould switching them over to IPsec give any better performance?Græme Ravenscroft • Technical Marketing Engineer
('gram', like the unit of measurement)
he/him
Please don't reboot your NGFW.
How can we make Arista ETM products better?
Comment
-
Originally posted by jcoehoorn View PostThe speed of a VPN link generally has more to do with the quality of the ISP on both ends and ability of the end-user hardware to offload the routing to the network chip rather than do it in the CPU. The specific VPN technology used is the least important factor.
Did some iperf3 tests with the OpenVPN site to site connection to have a baseline. Will see what difference it makes after.
Comment
-
Originally posted by donhwyo View PostSince they are fully licensed why not try wireguard? Supposed to have less overhead. I haven't got around to testing it yet.
Comment
-
Looking to do this between an Untangle firewall and a SophosXG/pfsense firewall, I assume ipsec would be the way to go? The Untangle is using an E3845 Atom CPU, where as the currently pfsense unit is using an i3-6100T.
The alternative is I'll configure OpenVPN client and use the client on a laptop, the aim is to remotely support a family network.
Comment
Comment