Solved

vpn firewall throughput

Posted on 2013-01-01
13
884 Views
Last Modified: 2016-03-23
I have a Netgear ProSafe VPN Firewall (FVS 318) and it is still working.

The Internet service provider has upgraded their speed (for the same price), but I am not seeing the speed increase.

If I go directly from the cable modem to my computer, I get around 25Mbps. Once the Netgear firewall is in-line, my connected speed drops way back down to around 5Mbps.
I know almost nothing about cyber-security, and this piece of equipment was purchased on the recommendation of someone who did know - but that was several years ago. All I know is I want to be safe while Internet surfing and safe from cyber-attack (however unlikely.) Worms moving from computer to computer in the home network are still a concern too.

My home network is 5 (wired) nodes, and off one drop there is a wireless TP-Link router (TL-WA801ND) for my daughter's iPod connectivity.

The Netgear Firewall is 10/100, but does the "100" speed only apply to wired connections between nodes on my home network? (and NOT Internet?)

I now see that it "only" has 12.5Mbps throughput, so is that why the 25Mbps signal is dropped or rejected or whatever, and drops down to less than 5Mbps?

Can I turn of the VPN functionality (if that is wise) and get a faster throughput (making it a firewall/router) ?

Or, if I want to see the high speed from the Internet provider, do I need to upgrade to a different VPN Firewall, with faster throughput? (Like the Netgear FVS318G-100NAS0)

Any help will be appreciated. Remember, I am spewing out buzzwords, not understanding this technology at all.

Thanks,

Dennis
0
Comment
Question by:dtleahy
  • 6
  • 5
  • 2
13 Comments
 
LVL 90

Assisted Solution

by:John Hurst
John Hurst earned 300 total points
ID: 38734883
You may need to replace your router with a newer and faster router.

I had a Linksys RV042 router and as the cable supplier in my area gradually raised speeds to "as high as" 25Mbits/sec, I could only get 8Mbits/second through the router. I could get 20Mbits/second directly connected.

I replaced the router with a Cisco RV042G Gigabit router and I now get between 17 and 20Mbits throughput depending on time of day a load.

So a simple router upgrade did it.  ... Thinkpads_User
0
 

Author Comment

by:dtleahy
ID: 38734890
Thanks for the quick reply, Thinkpads_User.

My understanding of the VPN capabilities is so limited, I don't know if I even use the device as a VPN or not - however, it is a hardware firewall, and I don't want to give up that functionality.

So, I would at least be looking for a firewall-router, or a firewall-switch.

Dennis
0
 
LVL 90

Expert Comment

by:John Hurst
ID: 38734905
I understood from your question that you also wanted the fastest internet speed. My response was to address that need.

Right now my fastest upload speed is still around 0.6Mbits/second, the VPN through my new RV042G is no faster than VPN through the older RV042. Both of these are hardware VPN devices and I have site to site tunnels connected to my main clients.

So a new router will not likely speed up VPN, but it probably will speed up browsing. I certainly am happy with my new router.

.... Thinkpads_User
0
 

Author Comment

by:dtleahy
ID: 38734998
Hi Thinkpads_User,

I appreciate your input. I kinda bounced around with my questions, but  I am not looking for just a router, but rather want to keep the hardware firewall functionality.

Based on Netgear calling mine a "10/100", I was quite surprised to see it has a maximum throughput of 12.5Mbps (that is not how it was originally advertised - or I did not know what spec to look at.).  And, I'm also surprised that my Internet didn't throttle back to fit that (even 12.5 would have been 2.5x faster than my current connection through the firewall.) The Internet dropped all the way beck to below 5Mbps.

The next Netgear in the line, at $139, the FGS318-100NAS has a 25Mbps throughput, but gets a lot of poor reviews.

So, I'm looking for recommendations for a relatively inexpensive hardware firewall-switch with at least a 25Mbps throughput. If I ever do need VPN functionality again I can (temporarily) plug in my old FVS318.

Thanks again for your assistance,

Dennis
0
 
LVL 90

Assisted Solution

by:John Hurst
John Hurst earned 300 total points
ID: 38735023
Where is your DHCP server?

Before getting the faster router (which includes my DHCP server), I got a 3-Com (HP) Gigabit switch. I had my Desktop plugged into the router and my laptop plugged into my switch. I was getting 100 Mbits/sec throughput (limited by the router). I moved the desktop to the switch and throughput promptly dropped in half. I concluded that the router (source of DHCP) plays a part.

I put the desktop back on the new faster router and now I get very high broadband speeds as well as very fast network transfers.

So my point is twofold then. A faster switch alone will not give faster transfers or broadband speeds, and, you need the fastest router (not switch) that you can get to obtain the best broadband speeds.

In my case, at least, all this stuff works together.
.... Thinkpads_User
0
 
LVL 90

Expert Comment

by:John Hurst
ID: 38735045
If you want a good commercial firewall, look at the Juniper firewalls. The SSG5 is a good entry level firewall with good speed ratings. I use these at clients, but the Internet speeds are lower at this point so we have not taxed the Juniper boxes to their limits.

The SSG5 can work as a VPN firewall and also includes a router if you wish to use it.
.... Thinkpads_User
0
Enabling OSINT in Activity Based Intelligence

Activity based intelligence (ABI) requires access to all available sources of data. Recorded Future allows analysts to observe structured data on the open, deep, and dark web.

 
LVL 26

Accepted Solution

by:
akahan earned 200 total points
ID: 38735534
Dennis,

You're pretty confused about the relationship between 10/100 and the speeds you're getting.

The 10/100 is a reference to hardware:  at one time, ethernet connections could accommodate only 10mbits/second as a result of constraints imposed by the hardware.

More modern hardware could accommodate speeds of up to 100mbits/second.
And now even more modern hardware accommodates speeds of up to 1000mbits/second (gigabit).

The designation 10/100 means that your router will happily talk to either of the first two generations of hardware at the rate they are capable of talking.  It'll also talk to gigabit-capable hardware, but the gigabit hardware will throttle back to accommodate you.  That's irrelevant here, because your internet connection doesn't exceed 100mbits/second.  So there's nothing about the 10/100 that creates a problem for you.

Your problem is that communications between LAN and WAN (the local network interface and the internet interface) on that particular router are capped at about 12.5mbits/second; this isn't a function of the 10/100 jacks, it's a function of the lack of brainpower (processing power) in the router.  It just can't think fast enough to allow faster throughput (though it will allow much faster throughput between machines on your own local network).

So if your incoming internet speed is higher than 12.5mbits/second, you won't get the benefit of the additional speed using this router, and there's nothing you can do about it short of changing routers.

You are not using the VPN in this router at all.  A VPN is a virtual private CONNECTION: it is a highly secure tunnel between two points.  You only have one point: your router.  The VPN would be used if you had two such routers at different offices that were talking to each other, or if you were using one of your laptops at Starbucks, and wanted to establish a secure connection to your home network.  Either of those scenarios would be one where you would use the VPN...but that's not what you're doing.

EVERY router is a firewall, in that it discards incoming packets that weren't anticipated.  There's no such thing as a router that is not a firewall.

So I would say that all you need is a router with faster LAN/WAN throughput; no need for a VPN router at all.

One that you might want to consider is a Cisco/Linksys RV042 or RV082; these workhorses were sold by the zillions, and are pretty well understood.  The RV042 10/100 version (there's a gigabit version now, but it's probably overkill) will accommodate 54mbits/second incoming (WAN to LAN) and 80mbits/second outgoing (LAN to WAN).
0
 

Author Comment

by:dtleahy
ID: 38735581
Thinkpads_User,
Ooooohhhhh that Juniper is spendy! Yikes, over $500. This is for a home network, and I can't justify one at that cost (even if it is worth every penny.)


akahan,
Well now I am much less confused. Thank you.

I have not heard "every router is a firewall" before. Are there ANY advantages (real-world  security) to a device hawked as a "hardware firewall" or is that just marketing/misnomer?

The Cisco/Linksys RV042 router you mention is 4 ports. I need 6 drops, so a switch with 8 ports seems like a good fit.

Any comments on the D-Link DSR-150 router? I cannot find much info on them, but at around $108, it is affordable (8 ports, 45Mbps firewall throughput, VPN throughput 25Mbps - if I ever need it)

(http://www.dlink.com/us/en/support/product/dsr-150)

Dennis
0
 
LVL 26

Assisted Solution

by:akahan
akahan earned 200 total points
ID: 38735600
The RV082 has eight ports, and is otherwise pretty much the same as the RV042, so that'd probably do it for you.

And yup, EVERY router is a hardware firewall.

The DSR-150 has a single WAN interface.  If you have only one internet service provider, that's fine.  A reason to have dual WAN interfaces (as offered by the RV042 and RV082) is you can have multiple ISPs (Cable and ADSL, for example) with automatic failover...if one of them goes down, the router automatically switches to the other.

Other than that, it's quite feature rich, and certainly adequate for the application you're describing if it does what its specifications say it does; my caveat is that I  haven't personally worked with it.
0
 
LVL 90

Expert Comment

by:John Hurst
ID: 38736158
I said above I use a Cisco RV042G which is brand new and very fast. I get full speeds on my network with it. Much less than a Juniper. There is an RV042 and an RV042G. Make sure to get the G model. I don't think there is a FV082G quite yet.

..... Thinkpads_User
0
 

Author Closing Comment

by:dtleahy
ID: 38736939
Thanks very much, thinkpads_user and akahan.<br /><br />At this time, and with my budget, the $108 pricetag on the D-Link DSR-150 Unified Services Router was the major factor over the $250 Cisco/Linksys RV082 (yes, I couldn't find a "-G" model to even get a price.)<br /><br />I ordered the D-Link unit (from Newegg, while they had that $108 price.)<br /><br />Dennis
0
 

Author Comment

by:dtleahy
ID: 38736975
Well, somehow I screwed-up on giving points. Wanted to give you both points, but as I got the most from the post of akahan (that was marked as the "accepted" solution), that was supposed to get 200 points and the other "assisted" solutions were supposed to get 100.

Thanks again for your help.

Dennis
0
 
LVL 90

Expert Comment

by:John Hurst
ID: 38737158
Thank you Dennis. You can always Request Attention if you wish to change things.
... Thinkpads_User
0

Featured Post

How your wiki can always stay up-to-date

Quip doubles as a “living” wiki and a project management tool that evolves with your organization. As you finish projects in Quip, the work remains, easily accessible to all team members, new and old.
- Increase transparency
- Onboard new hires faster
- Access from mobile/offline

Join & Write a Comment

Read about achieving the basic levels of HRIS security in the workplace.
Let’s list some of the technologies that enable smooth teleworking. 
How to install and configure Citrix XenApp 6.5 - Part 1. In this video tutorial we have explained step by step installation of Citrix XenApp 6.5 Server on Windows Server 2008 R2 is explained in this video. We have explained the difference between…
Internet Business Fax to Email Made Easy - With eFax Corporate (http://www.enterprise.efax.com), you'll receive a dedicated online fax number, which is used the same way as a typical analog fax number. You'll receive secure faxes in your email, fr…

707 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

10 Experts available now in Live!

Get 1:1 Help Now