VPN Speed

Associate
Joined
30 Dec 2003
Posts
289
I've recently set up some VPNs between a few different sites and noticed an annoying, difference in latency between two sites. Unfortunately I can't yet narrow down the cause(s) so have two options. I'll explain the set up first and then detail the issue.

Site A:
10Mb connection to JANET
Cisco 2691 router with Cisco PIX 506e firewall

Site B:
Zen Office Max Pro ADSL
Netgear DG834 router/firewall device

Site C:
Aquiss Office Max 90 ADSL
Draytek vigor 2800G router/firewall device

The authentication/encryption settings are the same from A-B and A-C so both ADSL routers are having to do the same work.

The first VPN was between A and B, and it worked ok, not mind blowing performance but since I hadn't used a VPN before I assumed the pings of almost 50ms between hosts in the two separate LANs was normal. Generally this was annoying but didn't stop things working.

Second up was the VPN from site A to C. I first configured this while using the previous ISP (BT, non MAX) and it worked really well. I noticed the A-C pings were way lower than A-B, in the order of 18-20ms, so 2.5x quicker. I am aware of an increase in latency going from normal ADSL to ADSL MAX so waited for the Aquiss connection to go live before posting here. Now I'm seeing pings of 22-26ms which would maybe account for the MAX/non-MAX latency. It's still miles quicker than A-B which makes the A-B slowness more annoying.

Now for the actual point of my post! Is the rubbish speed due to Zen or the Netgear, and if either are only partially responsible, which is likely causing the larger lag? Annoyingly I cannot use a Draytek v2800 at site B because Zen's MAX service won't work with it. I don't particularly care for their response to the problem (it's a BT/draytek issue) however valid it may be because I have had no such problems with MAX and the v2800 on two other Aquiss ADSL MAX connections.

Thanks
 
What happens if you ping the routers at both sites (ie forgo the VPN)?

It's possible it's partly Zen related: Zen terminate their Centrals in Rochdale whereas Enta terminate theirs in London.

There's no change in latency between IPStream and IPStream Max though, unless there's an issue with the line and interleaving gets switched on (and you can get it switched off).
 
good point, i didn't think to test the speed without the VPN. there is about a 20ms difference with Zen coming out the slower of the two. The routing probably accounts for some or all of that. I'll prob switch that connection to Aquiss eventually to keep all the branch office setups the same.
 
Back
Top Bottom