Want to win a PS4? Go Premium and enter to win our High-Tech Treats giveaway. Enter to Win

x
?
Solved

Which is generally faster, a VPN connection setup on a router/firewall or a Windows 2000 server?  Need to optimize VPN.

Posted on 2007-11-15
8
Medium Priority
?
1,317 Views
Last Modified: 2013-12-05
I have users in a remote new york office who are experiencing very poor VPN performance even though their local network is very fast and ours is very fast.  They are on a 11mbps line and our line is 3.0 mbps, and still the connection for them is slower than molasses.  We have a PIX 506e, but currently VPN traffic is being handled by our RRAS windows 2000 server.  Would moving the VPN to the PIX help with speed, and if not that, what can be done to troubleshoot these slowness issues?
0
Comment
Question by:QuiteSupersonic
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
8 Comments
 
LVL 4

Assisted Solution

by:gabbadar
gabbadar earned 600 total points
ID: 20290717
A router would technically be faster since the encryption/decryption would be hardware-driven.  I'm not sure how much performance gain you'd actually see between the two though.

Try a trace route between the two locations. If you've got different carriers there could be a hangup inbetween. If you need a more reliable connection between the two offices, an MPLS may be a better option.
0
 
LVL 1

Assisted Solution

by:AkermanIT
AkermanIT earned 600 total points
ID: 20292685
Directing your VPN cleint to authenticate to a  server inside your network will always be slower then having your PIX or a VPN concentrator preform the action. With ISP throttling connections between carriers you will still only be getting 256-512 Kbps. I have seen my push to 1Mbps but rarely and not for long. If you want better thru put look into an F5 or Juniper VPN concentrator or Citrix/Termianl services. Good luck!
0
 
LVL 19

Accepted Solution

by:
SteveH_UK earned 800 total points
ID: 20335269
Another aspect to the question is whether or not hardware offloading is actually being used.  Some, cheaper routers/firewalls do not use hardware to support VPN connections.  Also, there are VPN accelerators for Windows servers.  So, it is primarily a question of how much you spend.

If you spend the money on a VPN accelerator in Windows, and provide decent hardware, I wouldn't expect it to operate any slower that any other router/firewall.  This is also because the other bottlenecks, such as network speed, tend to be more important.

Of course, if you are talking about 10Gbit networks and the like, then get a really expensive, load-balancing set of firewall/router VPN concentrators!  But be prepared to spend, spend, spend...
0
Q2 2017 - Latest Malware & Internet Attacks

WatchGuard’s Threat Lab is a group of dedicated threat researchers committed to helping you stay ahead of the bad guys by providing in-depth analysis of the top security threats to your network.  Check out our latest Quarterly Internet Security Report!

 
LVL 19

Expert Comment

by:SteveH_UK
ID: 20335286
You may also want to look at WAN optimisation techniques, such as products offered by Packeteer.  These improve the performance of your WAN links, thereby improving your VPN performance.

Also, you may want to upgrade your clients and/or servers.  Are you using IPsec-only, LT2P/IPsec or PPTP?  LT2P and PPTP authenticate clients so they are not a direct comparison with many router implementations.
0
 
LVL 19

Expert Comment

by:SteveH_UK
ID: 20335303
The bandwidth you are talking about (11mbps and 3mbps)  only equate to around 1.2MB/s and 330KB/s.  Neither requires particularly powerful hardware, so I would consider looking into what other bottlenecks might be present.  How responsive is AD for example?  Or maybe your VPN server just needs more RAM!
0
 

Author Comment

by:QuiteSupersonic
ID: 20437795
please close this question.
0
 
LVL 19

Expert Comment

by:SteveH_UK
ID: 20439896
QuiteSupersonic, you must close the question, either by speaking to the Zone Advisor or by distributing the points.

See http://www.experts-exchange.com/help.jsp#hi9
0

Featured Post

What does it mean to be "Always On"?

Is your cloud always on? With an Always On cloud you won't have to worry about downtime for maintenance or software application code updates, ensuring that your bottom line isn't affected.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

OpenVPN is a great open source VPN server that is capable of providing quick and easy VPN access to your network on the cheap.  By default the software is configured to allow open access to your network.  But what if you want to restrict users to on…
If you use NetMotion Mobility on your PC and plan to upgrade to Windows 10, it may not work unless you take these steps.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Suggested Courses

610 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question