Which is generally faster, a VPN connection setup on a router/firewall or a Windows 2000 server? Need to optimize VPN.

I have users in a remote new york office who are experiencing very poor VPN performance even though their local network is very fast and ours is very fast.  They are on a 11mbps line and our line is 3.0 mbps, and still the connection for them is slower than molasses.  We have a PIX 506e, but currently VPN traffic is being handled by our RRAS windows 2000 server.  Would moving the VPN to the PIX help with speed, and if not that, what can be done to troubleshoot these slowness issues?
QuiteSupersonicAsked:
Who is Participating?
 
SteveH_UKConnect With a Mentor Commented:
Another aspect to the question is whether or not hardware offloading is actually being used.  Some, cheaper routers/firewalls do not use hardware to support VPN connections.  Also, there are VPN accelerators for Windows servers.  So, it is primarily a question of how much you spend.

If you spend the money on a VPN accelerator in Windows, and provide decent hardware, I wouldn't expect it to operate any slower that any other router/firewall.  This is also because the other bottlenecks, such as network speed, tend to be more important.

Of course, if you are talking about 10Gbit networks and the like, then get a really expensive, load-balancing set of firewall/router VPN concentrators!  But be prepared to spend, spend, spend...
0
 
gabbadarConnect With a Mentor Commented:
A router would technically be faster since the encryption/decryption would be hardware-driven.  I'm not sure how much performance gain you'd actually see between the two though.

Try a trace route between the two locations. If you've got different carriers there could be a hangup inbetween. If you need a more reliable connection between the two offices, an MPLS may be a better option.
0
 
AkermanITConnect With a Mentor Commented:
Directing your VPN cleint to authenticate to a  server inside your network will always be slower then having your PIX or a VPN concentrator preform the action. With ISP throttling connections between carriers you will still only be getting 256-512 Kbps. I have seen my push to 1Mbps but rarely and not for long. If you want better thru put look into an F5 or Juniper VPN concentrator or Citrix/Termianl services. Good luck!
0
Firewall Management 201 with Professor Wool

In this whiteboard video, Professor Wool highlights the challenges, benefits and trade-offs of utilizing zero-touch automation for security policy change management. Watch and Learn!

 
SteveH_UKCommented:
You may also want to look at WAN optimisation techniques, such as products offered by Packeteer.  These improve the performance of your WAN links, thereby improving your VPN performance.

Also, you may want to upgrade your clients and/or servers.  Are you using IPsec-only, LT2P/IPsec or PPTP?  LT2P and PPTP authenticate clients so they are not a direct comparison with many router implementations.
0
 
SteveH_UKCommented:
The bandwidth you are talking about (11mbps and 3mbps)  only equate to around 1.2MB/s and 330KB/s.  Neither requires particularly powerful hardware, so I would consider looking into what other bottlenecks might be present.  How responsive is AD for example?  Or maybe your VPN server just needs more RAM!
0
 
QuiteSupersonicAuthor Commented:
please close this question.
0
 
SteveH_UKCommented:
QuiteSupersonic, you must close the question, either by speaking to the Zone Advisor or by distributing the points.

See http://www.experts-exchange.com/help.jsp#hi9
0
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

All Courses

From novice to tech pro — start learning today.