Still celebrating National IT Professionals Day with 3 months of free Premium Membership. Use Code ITDAY17


Help with tunnel bandwidth

Posted on 2009-06-30
Medium Priority
Last Modified: 2012-05-07
Dear expert I am confuse with physical actual size and  VPN tunnel bandwidth.For example office has  a T1 mpls ckt 1536. At this location we are using DMVPN tunnel with a bandwidth size of 512k. I had a report about slow performance, when I did a sho interface  the physical interface reliable tx load was 50/255 and rx load was 125/255 when I checked tunnel interface the tx load was 10/255 and  rx load was 255/255 I wonder if  this mean that the tunnel is rece  100% of traffic in the amount of 512k and any traffic over will be place in a buffer or dropped  until space is available, please explain as this office normally report slow perform any time when tunnel  tx or rx load is max out, once tunnel  tx or rx load is not max out office works fine. I also checked in concord ehealth and did notice if the graph for the physical interface is 50 % the tunnel will be at 100% do this mean 1005 of the 512k what is on tunnel interface bandwidth
Question by:rcollie
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 4
  • 2

Expert Comment

ID: 24754359
Think of each direction, Tx and Rx, as a separate pipe. In a full duplex environment such as modern ethernet or ADSL, a composite utilization number is nearly useless or worse. Always look at each direction separately. 100% Rx utilization for anything other than a momentary burst will nearly guarantee performance problems and extensive packet loss, since the buffers in the network devices will surely become overrun in milliseconds or seconds, and packets then have no where to go but on the floor. Not only will you lose data inbound to you, but when ACKs for transmitted data are dropped, you will consume more Tx bandwidth with unnecesary retransmissions.

And you are correct in noticing that your physical interface utilization is of minimal value if your VPN pipe is rate-limited below your physical pipe. Only your vpn tunnel utilization will accurately reflect your network performance experience.

Your most cost effective choice to improve your network performance would be to analyze your traffic, determine which applications are critical and which are not, perhaps even by time of day, and shape your traffic accordingly. For instance, if your Rx traffic is primarily http responses to non-business related web browsing, use your firewall, router, or a proxy to limit hours of the day that open web browsing is permitted.

Your next choice is to increase bandwidth. But performing that traffic pattern analysis will benefit you no matter what.

Expert Comment

ID: 24814751
How's your search for knowledge progressing, rcollie ? :)

Author Comment

ID: 24831638
I need more info on the tunnel and how traffic is affected as I said when using some type of monitoring tool it show the physical interface not used that much but when I check the tunnel interface it shows it at 100 percent. I just need to be able to explain this before I show others output from monitoring tool
Looking for the Wi-Fi vendor that's right for you?

We know how difficult it can be to evaluate Wi-Fi vendors, so we created this helpful Wi-Fi Buyer's Guide to help you find the Wi-Fi vendor that's right for your business! Download the guide and get started on our checklist today!


Expert Comment

ID: 24898839
"...we are using DMVPN tunnel with a bandwidth size of 512k" Which carrier are you using? Most stateside carriers who provide this type of service offer management utilities as a part of your rate. They should have something optimized to show the actual bandwidth being utilized with respect to the bandwidth available in your rate limited tunnel. I thikn this should achieve your goal of displaying an accuraterepresentation of the tunnel utilization?

Author Comment

ID: 24904774
Dear expert I have change tunnel bandwidth to equal the size of the physical circuit for example on the t1 1536 bw I have also set this value on tunnel now when I check concord it shows a more accurate readying . but I am still confuse on with tunnel banwidth if the tunnel was default 8k and I hard code bandwidth to 1536k in which example will the traffic flow through quicker or is it just routing metric that the bandwidth is use for

Accepted Solution

Nothing_Changed earned 2000 total points
ID: 24917725
depending on if you changed that bandwidth (not sure what commands you used?) in the T1 controller or in the VPN config or the router interface, you wither changed what size pipe the tunnel would max out at, or you changed a routing parameter that doesnt really affect actual performance at all, jsut how the router reports bandwidth used.

If it's a vendor provided vpn solution, and that vpn shares bandwidth with some voice circuits, your network changes , depending on where you make them, could impact your voice circuits. If it is a "bundle circuit" as some vendors call it, for instance.

Featured Post

Connect further...control easier

With the ATEN CE624, you can now enjoy a high-quality visual experience powered by HDBaseT technology and the convenience of a single Cat6 cable to transmit uncompressed video with zero latency and multi-streaming for dual-view applications where remote access is required.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

#Citrix #Citrix Netscaler #HTTP Compression #Load Balance
If you’re involved with your company’s wide area network (WAN), you’ve probably heard about SD-WANs. They’re the “boy wonder” of networking, ostensibly allowing companies to replace expensive MPLS lines with low-cost Internet access. But, are they …
After creating this article (, I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Windows 10 is mostly good. However the one thing that annoys me is how many clicks you have to do to dial a VPN connection. You have to go to settings from the start menu, (2 clicks), Network and Internet (1 click), Click VPN (another click) then fi…
Suggested Courses

688 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question