Solved

Which is generally faster, a VPN connection setup on a router/firewall or a Windows 2000 server?  Need to optimize VPN.

Posted on 2007-11-15
8
1,307 Views
Last Modified: 2013-12-05
I have users in a remote new york office who are experiencing very poor VPN performance even though their local network is very fast and ours is very fast.  They are on a 11mbps line and our line is 3.0 mbps, and still the connection for them is slower than molasses.  We have a PIX 506e, but currently VPN traffic is being handled by our RRAS windows 2000 server.  Would moving the VPN to the PIX help with speed, and if not that, what can be done to troubleshoot these slowness issues?
0
Comment
Question by:QuiteSupersonic
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
8 Comments
 
LVL 4

Assisted Solution

by:gabbadar
gabbadar earned 150 total points
ID: 20290717
A router would technically be faster since the encryption/decryption would be hardware-driven.  I'm not sure how much performance gain you'd actually see between the two though.

Try a trace route between the two locations. If you've got different carriers there could be a hangup inbetween. If you need a more reliable connection between the two offices, an MPLS may be a better option.
0
 
LVL 1

Assisted Solution

by:AkermanIT
AkermanIT earned 150 total points
ID: 20292685
Directing your VPN cleint to authenticate to a  server inside your network will always be slower then having your PIX or a VPN concentrator preform the action. With ISP throttling connections between carriers you will still only be getting 256-512 Kbps. I have seen my push to 1Mbps but rarely and not for long. If you want better thru put look into an F5 or Juniper VPN concentrator or Citrix/Termianl services. Good luck!
0
 
LVL 19

Accepted Solution

by:
SteveH_UK earned 200 total points
ID: 20335269
Another aspect to the question is whether or not hardware offloading is actually being used.  Some, cheaper routers/firewalls do not use hardware to support VPN connections.  Also, there are VPN accelerators for Windows servers.  So, it is primarily a question of how much you spend.

If you spend the money on a VPN accelerator in Windows, and provide decent hardware, I wouldn't expect it to operate any slower that any other router/firewall.  This is also because the other bottlenecks, such as network speed, tend to be more important.

Of course, if you are talking about 10Gbit networks and the like, then get a really expensive, load-balancing set of firewall/router VPN concentrators!  But be prepared to spend, spend, spend...
0
Comprehensive Backup Solutions for Microsoft

Acronis protects the complete Microsoft technology stack: Windows Server, Windows PC, laptop and Surface data; Microsoft business applications; Microsoft Hyper-V; Azure VMs; Microsoft Windows Server 2016; Microsoft Exchange 2016 and SQL Server 2016.

 
LVL 19

Expert Comment

by:SteveH_UK
ID: 20335286
You may also want to look at WAN optimisation techniques, such as products offered by Packeteer.  These improve the performance of your WAN links, thereby improving your VPN performance.

Also, you may want to upgrade your clients and/or servers.  Are you using IPsec-only, LT2P/IPsec or PPTP?  LT2P and PPTP authenticate clients so they are not a direct comparison with many router implementations.
0
 
LVL 19

Expert Comment

by:SteveH_UK
ID: 20335303
The bandwidth you are talking about (11mbps and 3mbps)  only equate to around 1.2MB/s and 330KB/s.  Neither requires particularly powerful hardware, so I would consider looking into what other bottlenecks might be present.  How responsive is AD for example?  Or maybe your VPN server just needs more RAM!
0
 

Author Comment

by:QuiteSupersonic
ID: 20437795
please close this question.
0
 
LVL 19

Expert Comment

by:SteveH_UK
ID: 20439896
QuiteSupersonic, you must close the question, either by speaking to the Zone Advisor or by distributing the points.

See http://www.experts-exchange.com/help.jsp#hi9
0

Featured Post

Free Tool: Path Explorer

An intuitive utility to help find the CSS path to UI elements on a webpage. These paths are used frequently in a variety of front-end development and QA automation tasks.

One of a set of tools we're offering as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Remote desktop connection frequent connection lost 5 93
Event 488 and 413 pop up after in-place server upgrade 4 40
IPSec firewall rules 1 35
harddrive crash 6 36
I've written this article to illustrate how we can implement a Dynamic Multipoint VPN (DMVPN) with both hub and spokes having a dynamically assigned non-broadcast multiple-access (NBMA) network IP (public IP). Here is the basic setup of DMVPN Pha…
Let’s list some of the technologies that enable smooth teleworking. 
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Windows 10 is mostly good. However the one thing that annoys me is how many clicks you have to do to dial a VPN connection. You have to go to settings from the start menu, (2 clicks), Network and Internet (1 click), Click VPN (another click) then fi…

739 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question