Hi, we have several staff working remotely as a result of covid but as part of our compliance requirements all traffic from these machines needs to run through a hardware firewall. We were using OpenVPN but switched to WireGuard full tunnel for better speeds. Everything works fine but we are not seeing the speeds I would have hoped through it. I suspect there is a fairly simple fundamental reason but would love some helping in working out what it is! The setup looks like this:
Datacentre
1Gbps each way fibre internet connection
Untangle running 16.5.0 as a VM on Hyper-V - 8GB RAM, 4vCPUs on a Xeon E5-2430, 500GB disk on a SAS RAID 10 array - no hardware resources look remotely loaded when running a speed test on this
MTU set to 1500 and tested to confirm
WG set to use 8.8.8.8 as the DNS server with
Office
Starlink internet - 120-150MB down and 20-30MB up
MTU set to 1500 and tested to confirm
Untangle Firewall running 16.5.0 on NUC (i5, 8GB, 250GB SSD)
Various laptops that work from here or from home\out on the road, hence no site to site VPN but instead all setup as roaming full tunnel clients
Using a speedtest website such as fast.com with no VPN we see the Office speeds, with the VPN I can't break 30MB down and 7MB up. This is true on alternative internet connections, some staff have fibre internet at home (300MB down and 30MB+ up) and still can't break the 30MB down on an online speed test.
I've tried playing with QoS rules to priortise WG traffic (based on IP ranges on each side, port number and interface) on both UT's in the above example but it made no difference. Also set both UT's to bypass the WG traffic and adjusted QoS accordingly again to no avail.
Where do I go next with this?
Thanks
Andy
Datacentre
1Gbps each way fibre internet connection
Untangle running 16.5.0 as a VM on Hyper-V - 8GB RAM, 4vCPUs on a Xeon E5-2430, 500GB disk on a SAS RAID 10 array - no hardware resources look remotely loaded when running a speed test on this
MTU set to 1500 and tested to confirm
WG set to use 8.8.8.8 as the DNS server with
Office
Starlink internet - 120-150MB down and 20-30MB up
MTU set to 1500 and tested to confirm
Untangle Firewall running 16.5.0 on NUC (i5, 8GB, 250GB SSD)
Various laptops that work from here or from home\out on the road, hence no site to site VPN but instead all setup as roaming full tunnel clients
Using a speedtest website such as fast.com with no VPN we see the Office speeds, with the VPN I can't break 30MB down and 7MB up. This is true on alternative internet connections, some staff have fibre internet at home (300MB down and 30MB+ up) and still can't break the 30MB down on an online speed test.
I've tried playing with QoS rules to priortise WG traffic (based on IP ranges on each side, port number and interface) on both UT's in the above example but it made no difference. Also set both UT's to bypass the WG traffic and adjusted QoS accordingly again to no avail.
Where do I go next with this?
Thanks
Andy
Comment