Still celebrating National IT Professionals Day with 3 months of free Premium Membership. Use Code ITDAY17

x
?
Solved

100MB VPN tunnel to Colo Slowness

Posted on 2014-04-26
14
Medium Priority
?
874 Views
Last Modified: 2014-05-10
We have moved our HQ to a new building and are using a 100MB VPN site-to-site tunnel as our primary until we get our 100 MB MPLS line terminated and up.
 Our issue is any access to network resources at our Colo is incredibly sluggish. For example, Shared folders downloads are hitting speeds like 92KBs or maybe hitting 1-2MBs and will take 2-3 hours just to download a 300MB file.  
We have an Hub and Spoke setup.
Here is an general overview:
 
   HQ LAN ---> ASA 5512 100MB VPN endpoint ----> Colo 5510 endpoint

We have a 50MBs DS3 connection at our Colo.
0
Comment
Question by:RenoGryphon
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 7
  • 4
  • 3
14 Comments
 
LVL 57

Expert Comment

by:giltjr
ID: 40024639
Need some clarification on your exact connection and your throughput.

First big B means bytes and little b means bits.  I doubt very much you have a 100 MByte per second or a 50MByte per second connection.  My guess is they are 100 Mbits or 50 Mbits per second.

Also need to verify what you connections are.  A DS3 is a 45Mbps link, not 50 Mbps.  A 45Mbps link can have a maximum of 4.5MBytes per second.  So at the Colo is it a 45Mbps DS3?  

What speed link do you have at your HQ?

When you stated your throughput is maxing out at 1-2MBs did you really mean 1-2MBytes per second or did you mean 1-2Mbits per second?
0
 
LVL 98

Expert Comment

by:John Hurst
ID: 40024674
VPN uses the slow side upload speed. So if your line is DSL 100 megabits/sec down and 1 megabit/sec up, then what you see is entirely normal. You need a faster upload speed to fix this.
0
 

Author Comment

by:RenoGryphon
ID: 40024679
Sorry, I did kind of rush when I was typing this.

Our main line at our Colo is a 50mbps connection. Our original HQ was using a DS3 line (45mbps), but the new HQ will be getting a MPLS 100mbps line. However, until that's is install, we are using site-to-site 100mbps VPN as our primary.

Excuse the typos from before, everything is in bits per second, not Bytes. Lol Don't want to want to seem like a total fool, at least not just yet.
0
Industry Leaders: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

 

Author Comment

by:RenoGryphon
ID: 40024680
John,
 As far as I aware the Internet connection we have is 100mbs Up and down. Let me just confirm this once more.
0
 
LVL 98

Expert Comment

by:John Hurst
ID: 40024682
Until you get your new MPLS, I think what you are seeing with the existing setup is normal.
0
 
LVL 98

Expert Comment

by:John Hurst
ID: 40024685
If you are really getting 100 megabits both ways, check the MTU size.

Default MTU is 1500 which fragments VPN packets unduly. Set MTU to 1492 or a bit less and that may improve speed.
0
 

Author Comment

by:RenoGryphon
ID: 40024686
I was afraid you'd say that. The new MPLS won't be turned up for another 10 days. This company has kind screwed up their timing on everything. Is there anything we can do in the mean time?
0
 
LVL 98

Expert Comment

by:John Hurst
ID: 40024688
Try adjusting MTU to see if you can get some improvement.
0
 
LVL 57

Expert Comment

by:giltjr
ID: 40024740
Still a little confused.

--> "Our main line at our Colo is a 50mbps connection"

--> "... we are using site-to-site 100mbps VPN as our primary."

Does this mean you have two network connections at the Colo, a 100 Mbps Internet connection that VPN tunnel goes over and then a second 50 Mbps connection that is used for something else?

Have you done a packet capture while doing a file open/copy/download?

VPN tunnels do cause problems with MTU and fragmentation.  

What all goes over the VPN tunnel?  Could it be overloaded?  Could your Internet connection be overloaded?
0
 

Author Comment

by:RenoGryphon
ID: 40024745
50mbps (Windstream line) ---> Colo data center ----> soon to be 100mbps mpls ( Windstream) ---> HQ

Current primary line until
  50mbps ---> Colo---> 100mbps VPN Asa 5512 ---> Colo Asa 5510 ---> Colo data Center
0
 

Author Comment

by:RenoGryphon
ID: 40024747
Im  heading to our HQ now. I'll do some packet capturing once I'm there.
0
 
LVL 57

Expert Comment

by:giltjr
ID: 40024814
Sorry, still confused.  You seem to show two Colo connections.  Could you fill in the values for each S# with the speed of each network connection?

Colo server <-- S1 --> Colo ASA <-- S2 --> Internet <-- S3 --> HQ ASA <-- S4 -->

S1 =
S2 =
S3 =
S4 =

Right now to me it seems like somewhere you have a 50 Mbps connection, which would limit your max. transfer to 50 Mbps, which is still way faster than you are currently getting.
0
 

Accepted Solution

by:
RenoGryphon earned 0 total points
ID: 40043432
This has been resolved, thanksful! Sorry for the late reply.
Issue was with auto-negotiation and  MTU fragmentation bit.

Once we configured both of these on our ASA outside interface the tunnel begin to utilize the entire 50mbps --- both download and upload
0
 

Author Closing Comment

by:RenoGryphon
ID: 40055661
It resolved the initial problem?
0

Featured Post

Free Tool: Site Down Detector

Helpful to verify reports of your own downtime, or to double check a downed website you are trying to access.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Imagine you have a shopping list of items you need to get at the grocery store. You have two options: A. Take one trip to the grocery store and get everything you need for the week, or B. Take multiple trips, buying an item at a time, to achieve t…
A 2007 NCSA Cyber Security survey revealed that a mere 4% of the population has a full understanding of firewalls. As business owner, you should be part of that 4% that has a full understanding.
Have you created a query with information for a calendar? ... and then, abra-cadabra, the calendar is done?! I am going to show you how to make that happen. Visualize your data!  ... really see it To use the code to create a calendar from a q…
How to fix incompatible JVM issue while installing Eclipse While installing Eclipse in windows, got one error like above and unable to proceed with the installation. This video describes how to successfully install Eclipse. How to solve incompa…
Suggested Courses

705 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question