[Openswan Users] IPSec Traffic Slow in one direction

Harald Scharf h.scharf at nestec.at
Thu Mar 15 13:46:38 EDT 2007


Hello, folks

 

After solving the MTU problem with your help (thanks for this, and yes:
the NAT box droped the 

icmp frag...), I now have another problem.

 

In my setup, using padlock_aes as accelerator, the ipsec traffic is 2-3
times faster

sending than receiving.

 

When I copy a file with scp to a server behind the vpn, I get about
30-40 MBit/s,

but when I transfer the same file from the server to the client, the
speed is

at about 15 to max. 20 MBit/s.

 

The error counters on the interfaces are all zero, dmesg does not tell
anything unusual.

 

What I can tell is, that the "sending" bandwidth is exactly the same, as
when I do 

NOT use padlock_aes.

 

My esp setting is aes128-sha1.

 

Any suggestions, any hints for me?

 

tia

 

Harald

 


NESTEC - Die IT Security & Messaging Distribution mit Personlichkeit
GFi Software - BitDefender - NOD32 - BRICKS ISS - pdfMachine
2X Terminal & ThinClient Solutions -Accunetix
Besuchen sie uns: www.nestec.at


-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://lists.openswan.org/pipermail/users/attachments/20070315/baf38a23/attachment.html 


More information about the Users mailing list