Solved

VPN 3DES Encryption.  What kind of bandwidth overhead comes with this encryption scheme?

Posted on 2003-11-13
3
5,239 Views
Last Modified: 2007-12-19
I currently have ADSL through a company, 1436Kbs Download/256Kbs Upload.  I am currently using a VPN solution with 3DES encryption.  I have this ADSL VPN 3DES Encryption DSL Modem/Router at my office.  When I connect to it fromhome, using drive/folder mappings or VNC it is Extremly Slow.  If I use Windows Remote Desktop without the VPN and turn all the Remote Desktop settings to low, the session isn't so bad.  I am wondering how much overhead this 3DES encryption might have, being that my upload speed is 256Kbs.  Another thing is that I purchase this VPN solution from a DSL provider, and their solution is so you can have teleworkers and other VPN Remote locations (VPN Router to VPN Router).  I am starting to think this not a viable situation:

3DES overhead.
Multiple Teleworkers and/or Multiple VPN locations.
Possiblility of people behind VPN router using up/down bandwidth.

All limited to 256Kbs.

Ok, the bandwidth is NOT their for someone to do what is listed above.  I guess I am just more curious about the bandwidth overhead of 3DES, and how it would play along with a remote desktop application such as VNC.

Thanks,

KrAzY
0
Comment
Question by:KrAzY
3 Comments
 
LVL 13

Accepted Solution

by:
td_miles earned 250 total points
Comment Utility
IPSec overhead is not that great.

Average size of packet is 404 bytes.
http://advanced.comms.agilent.com/routertester/member/journal/JTC_003.html

IPSec overhead is 32 bytes.
http://www.linuxsecurity.com/feature_stories/yavipin-vpn.html

Therefore IPSec overhead is approx 8% for "average" Internet packets.

I think the difference you are seeing is due to the windows remote desktop doing better cacheing and hence beating VNC. I find the same thing even if I am not using a VPN, it is more usable to have windows terminal server in admin mode, rather than to use VNC. There is development deing done with VNC, so it might support better cacheing soon.

If you need to access remote files/folders then you might want to look into using offline folders, then you can work on a local copy and not have to worry about VPN. Either sync when you are next in the office, or set it up to sync when idle, so that you don't notice it.
0
 
LVL 79

Expert Comment

by:lrmoore
Comment Utility
Agree with td_miles. VNC is your weak link,  not the VPN.
You might have better luck if you reduce the default MTU on the server that you are VNC'ing into.
It is the overhead of the pppoe on the DSL, and not the 3DES encryption that is killing you.
Remote desktop connect/Terminal Services is MUCH faster than VNC.
You might want to look at TightVNC. I use it to connect to a system that does not support Remote Desktop - over a 3DES VPN (over cable vs DSL) and never have a problem.
http://www.tightnvc.com


0
 
LVL 11

Author Comment

by:KrAzY
Comment Utility
Thank you for all the information.
0

Featured Post

Do You Know the 4 Main Threat Actor Types?

Do you know the main threat actor types? Most attackers fall into one of four categories, each with their own favored tactics, techniques, and procedures.

Join & Write a Comment

For a while, I have wanted to connect my HTC Incredible to my corporate network to take advantage of the phone's powerful capabilities. I searched online and came up with varied answers from "it won't work" to super complicated statements that I did…
I've written this article to illustrate how we can implement a Dynamic Multipoint VPN (DMVPN) with both hub and spokes having a dynamically assigned non-broadcast multiple-access (NBMA) network IP (public IP). Here is the basic setup of DMVPN Pha…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

728 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

9 Experts available now in Live!

Get 1:1 Help Now