?
Solved

VPN Concentrator Shows Low Tx/Rx rates.

Posted on 2007-11-14
7
Medium Priority
?
987 Views
Last Modified: 2008-08-13
I have a Cisco VPN Concentrator that remote users connect to/through so that they can use Network resources.  There are usually 10-15 connections on any given day and they are sending and receiving data just fine.  Every now and then, a connection will get terminated and at times a connection will be dog slow.
I can go to Administer Sessions to get statistics on who is connected, how long they have been connected, from where are they connected and can even ping the address to which they are assigned. When I get a 25ms return on the ping and see that they have enormous Tx/Rx rates, I know they have a solid connection.
I guess I have a couple of questions:
1)  Why would several users at the same location have differences in connection, i.e. user 1,2 & 3 connects and is Tx/Rx fine and has the normal 25ms ping where user 4 connects and he is having all kinds of issues with the connection?
2)  What "things" could cause this?
3)  Is there a way to increase the throughput or "open the pipe" on the concentrator to make things faster?
0
Comment
Question by:itgroup1
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
7 Comments
 
LVL 3

Expert Comment

by:mediaonegraphics
ID: 20282735
What type of VPN's are you using?  Depending on the overhead for the connection, your pipe and the end users isp you could be dropping  or incorrectly fragmenting packets.
0
 

Author Comment

by:itgroup1
ID: 20282751
We are using a Cisco VPN 3000 Concentrator. We are using Cisco VPN Clients 4.*.*
0
 
LVL 2

Accepted Solution

by:
cshanea0 earned 2000 total points
ID: 20283140
I'm assuming a couple of things from what you said.
1. All of your 4 users are at the same remote location using the same connection to the internet.
      a. If this is true, the network connection should not be the problem.
      b. If this is not true, you might be having a problem with either routing(i.e. same subnet being used on clients network and destination network) from one of the connections or it might be that the one connection is having problems with packet loss, bad connection& etc..
2. They are all using the same version of the Cisco VPN Client
      a. I've seen differences between the Cisco clients, especially from version 4.x to 5.x
3. They are all setup using the same Group in your VPN Concentrator.
      a. Connection specifics are setup in the groups.  If they are using different groups, they the encryption used could be different, the routes that are sent over the vpn connection could be different& etc.  Could be your problem.
4. They are all connecting to the same device/server/product on the other side of the VPN connection
      a. Check your destination server and what is being run.  It might be that the one having the problem is doing something different from the others.
      b. It might also be that the one having problems is using a protocol that is on a lower CoS (Class of Service) and there data is being dropped.  Assuming that you are using CoS.

If any of the above are different between the users that might be where your problem is.  Other than that there might be a problem with the clients PC.  Are they having high cpu or hard disk usage on the client pc?  also, are you using Bandwidth Policies (config - policy management - traffic management - BW policies) applied on your interface, config - interfaces - "Bandwidth" tab.  Though a bandwidth policy should be affecting all users equally as it is set to apply to each connection, not overall.
0
What does it mean to be "Always On"?

Is your cloud always on? With an Always On cloud you won't have to worry about downtime for maintenance or software application code updates, ensuring that your bottom line isn't affected.

 

Author Comment

by:itgroup1
ID: 20283241
1. All of your 4 users are at the same remote location using the same connection to the internet.
      a. TRUE
2. They are all using the same version of the Cisco VPN Client
      a. Most are using 4.8.02 but no they are not all the same. Concentrator.
3. They are all setup using the same Group in your VPN Concentrator.
      a. Same group
4. They are all connecting to the same device/server/product on the other side of the VPN connection
      a. Check your destination server and what is being run.  It might be that the one having the problem is doing something different from the others.  Good Point. I will check into it.

      b. It might also be that the one having problems is using a protocol that is on a lower CoS (Class of Service) and there data is being dropped.  Assuming that you are using CoS.  I do not know or am not familiar with this concept (CoS). I will have to research this.

Are they having high cpu or hard disk usage on the client pc? Possibly issues with client PC.

We have no bandwidth Policies (config - policy management - traffic management - BW policies) applied on your interface, config - interfaces - "Bandwidth" tab.  I will look into this.

Thank you, I will let you know what I find out.
/Sf
0
 
LVL 2

Expert Comment

by:cshanea0
ID: 20283686
Class of Service is just a way of prioritizing your more important traffic at a higher level than the lower traffic

Class A: RDP (Terminal Services)
Class B: Email
Class C: http, web

This way if your connection is saturated, your router will know to drop the web traffic while still allowing the higher services to function at a specific  rate.
0
 
LVL 32

Expert Comment

by:harbor235
ID: 20290704

What model VPN 3000 do you have? Its really hard diagnosing your problem with knowing your architecture.

harbor235 ;}
0
 

Author Comment

by:itgroup1
ID: 20291348
harbor235,
It is a VPN3005.
The problem, from what I can see and the help I received from cshanea0 to isolate the issue, is more than likely a wireless connectivity problem between the client and their ability to stay connected to a Cisco WAP.
To clarify things Client --> to WAP --> to Router --> to Backbone --> to HQ (VPN) --> Authentication --> Networked with HQ.  Make sense?
So we have several users who work this way from various locations and they rarely get disconnected if ever.  However, those at this "new site" where there are tons of Radio and TV stations in the area, a new wireless telephone system in the site, have  hard time staying connected wirelessly thus dropping the VPN connection.
I am setting up a computer via hard wire this afternoon to prove that it isn't the internal LAN (new wiring, etc.) nor is it the router (based on my limited knowledge by looking at it). Something is causing the drop on their wireless connections. How to determine that I haven't quite figured out yet.
/sf
0

Featured Post

WatchGuard's M Series Appliances - Miecom Approved

WatchGuard's newest M series appliances were put to the test by Miercom.  We had great results and outperformed all of our competitors in both stateless and stateful traffic throghput scenarios! Ready to see how your UTM appliance stacked up? Download the Miercom Report!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

In the hope of saving someone else's sanity... About a year ago we bought a Cisco 1921 router with two ADSL/VDSL EHWIC cards to load balance local network traffic over the two broadband lines we have, but we couldn't get the routing to work consi…
Every server (virtual or physical) needs a console: and the console can be provided through hardware directly connected, software for remote connections, local connections, through a KVM, etc. This document explains the different types of consol…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Suggested Courses
Course of the Month9 days, 13 hours left to enroll

762 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question