Saturday, May 2, 2020

New FTTH connection, problems with SSL VPN, slow file opening

Hi,

i'm here to ask help to identify the root cause of a FTTH connection that is acting very poorly to open files via SSL VPN.

Here the spec:

  • 60 mbit up/down symmetic FTTH Connection. Is a business grade one with bandwidth reservation (600€/month)
  • Zywall USG 210 Router Firewall.
  • The server on i'm opening the files is a Windows 2016 file server VM, full patched, 4 core, 6 gb RAM.
  • The infrastracture in new: 2 HP DL380 Gen10, 10 gbit networking between the 2 esxi host and principal switch

Previusly, we had a RDSL 15 mbit download and 3 mbit up at that site and opening a file took actually less time.

What i'm seeing: when i'm connected via SSL VPN (provided by the Zywall) to that server, if i try to open a 3 Mbyte excel file i get Excel freezing for about 10 second, then i see that excel is actually opening the file, i see the progress about at 15% increments, each one last about 3/4 second.

Total time to open a 3 mbyte file is about 40 second. This doesn't change if i use my workstation or another, or if i have Excel already opened or not.

What i've done until now:

  • Tested bandwidth: i have a full 60 mbit down/60 mbit up with 2/3 msec ping from a speedtest
  • I've adjust the MTU of the wan port to 1490, as i see it started to fragment at 1464 size and does not at 1462
  • Running iperf from my home connection using VPN i get transfer speed about 12/15 Mbits. I have a 100/20 mbit connection at home and it was not loaded with other tasks at the moment (netflix,ecc)
  • The problem does not occupr on local Lan
  • Running Wireshark at my point. I get some TCP Spurios Rentransmission error and TCP Dup ACK error repeatly.

In wireshark i tried to get some data (this data has been created today, when the performance seems a little better but i'm the only one connected today, yesterday with 5 people via VPN the opening time in SMB2 report was 23 seconds)

https://imgur.com/a/2twMyA9

SMB2 Service Response Time Statistics - Ethernet 2:

Index Procedure Calls Min SRT (s) Max SRT (s) Avg SRT (s) Sum SRT (s)

---------------------------------------------------------------------------

SMB2

Close 6 208 0.017751 0.123955 0.027319 5.682350

Create 5 205 0.018134 0.123470 0.030133 6.177226

Find 14 30 0.050237 0.087804 0.056980 1.709402

GetInfo 16 92 0.018054 0.104919 0.025832 2.376504

Ioctl 11 16 0.018615 0.057483 0.025317 0.405076

Read 8 54 0.018147 1.829909 0.245593 13.262049

Tree Connect 3 6 0.018539 0.022023 0.019451 0.116708

Write 9 12 0.018514 0.066883 0.023869 0.286423

SMB2

---------------------------------------------------------------------------



No comments:

Post a Comment