Microsoft Server OS
--
Questions
--
Followers
Top Experts
In other words, drag and drop, communication to the server on either end is horrendously slow, file transfer, email updates, etc... unworkable because its too slow. We have a T1 going out and coming in to each location.. there should be plenty of bandwith available. Obviously the rdp protocol is working... term serv is fast, fast, fast!!
So my question is.... where do I begin to troubleshoot why file transfers are slow between the two locations outside of the terminal serv? Is there a protocol or port or bandwith throttle inherrent in watchguard that has to be enabled? Solving this problem would probably garner me a raise in my newfound job. PLEASE HELP!
Zero AI Policy
We believe in human intelligence. Our moderation policy strictly prohibits the use of LLM content in our Q&A threads.
Please check and update about the results.
Thank you.
Additionally there are 12 policies in place:
FTP
HTTP
RDP
Ping
Watchguard IPsec
Watchguard
Outgoing
BOVPN - Allow out
BOVPN - Allow in
Tunnel traffic out
Tunnel traffic in
Any Optional 1






EARN REWARDS FOR ASKING, ANSWERING, AND MORE.
Earn free swag for participating on the platform.
Let us say when the peers negotiate SA for VPN, they also negotite path MTU, as 1400; also they decide that at this MTU all the packets would be sent with DF (don't fragment) bit set,
If such is the case, then the IPSec communication would also proceed with the same DF bit settings.
When we set DF to clear; the FB has the flexibility to fragment the IPSec packets if needed.
Many a times fragmentation is needed for the communication to proceed.
I think you have used VPN wizard ti create tunnel; hence the name BOVPN - Allow in/out; this is paractise is ANY service; you can edit the service and go to Properties tab; you would notice for Port/Protocol Any is mentioned. This allows traffic between the ends on all ports/protocols.
Please advice if making the above change if any improvement is seen.
Thank you.
2008-07-22 15:01:31 Deny 10.0.2.254 192.168.0.33 icmp-Dest_Unreach code(3) Firebox tunnel.1/IPsec icmp error with data src_ip=192.168.0.33 dst_ip=10.0.2.254 pr=netbios-ns/udp src_port=137 dst_port=137 src_intf='0-External' dst_intf='0' cannot match any flow, drop this packet 106 64 (internal policy) 13
I get this message when trying to transfer a file from one server to a desktop in my remote location. A 30MB file was going to take 30 minutes! It finally times out... It appears I'm having a problem with port 137?
Above log indicates that the firebox is not able to match the traffic with any existing flow/policy and is deliberately dropping it.
As you have any services opened between the subnets this should all traffic; by default the BOVPN-Allow service is created as:
From tunnel-name; to ANY
Can you change it to reflect as below:
Allow-in
From Remote-subnet; to local-subnet
Allow-out
From local-subnet; to remote-subnet
Save to firebox and check if this makes any difference.
Thank you.

Get a FREE t-shirt when you ask your first question.
We believe in human intelligence. Our moderation policy strictly prohibits the use of LLM content in our Q&A threads.
My initial problem was speed. I have a T1 (1.5MB) connected between my two offices. I am attempting to transfer a 30mb file between the two offices via a VPN tunnel. When its actually downloading, it initiatly says 20min... drops to 10min and usually gets done in 6-7min or a little less. In a perfect world... that should equate to about a 3min transfer rate. However, this 6-7 minute transfer rate would include latency and overhead instead? If you agree I'm correct... than I guess I've wasted your time... which I really hope I'm not...
but if not, what do you think my download time should be for a 30 mb file across a T1?
I will try your suggestion in the morning and report back my findings... I'll keep my fingers crossed.
You cannot expect the same speed which you might otherwise get when doing FTP; if you have noticed on the same link if you were to do scp instead of FTP; the speed drastically reduces.
Now think about a solution where we have encryption/authentication/
Hope I am able to clarify.
Thank you.






EARN REWARDS FOR ASKING, ANSWERING, AND MORE.
Earn free swag for participating on the platform.
Microsoft Server OS
--
Questions
--
Followers
Top Experts
The Microsoft Server topic includes all of the legacy versions of the operating system, including the Windows NT 3.1, NT 3.5, NT 4.0 and Windows 2000 and Windows Home Server versions.