Tuesday, April 13, 2021

Cisco Router + IPSec VPN + performance issues

Hi all

Currently facing an issue where we are noticing a gradual performance hit in one of our satellite offices which contains under 10 staff.

The office contains

- A 1000Mbps or 1Gbps fiber link supplied via the ISP provided Huawei NTU
- All traffic routes through a IPSec VPN, not split tunneling
- Cisco RV325 router ( might not be the best - throughput for IPSec VPN caps at 100 Mbps )
- handles the internal network DHCP
- handles the connection to the NTU
- handles the IPSec VPN

What I'm experiencing is that over the course of say a 1 hour period, when I'm plugged directly into the router ( avoiding any other networking equipment ) I run a basic ping test to the ISP default gateway or the LAN port on the NTU and the same test to the internet gateway address which begins at say 2 - 3ms, but eventually increases to 700 - 800ms. Speed tests when good are around 45Mbps but then drop to 3 - 4 Mbps.

At this point in time we have approx. 5 - 6 staff accessing the internet, taking Teams calls, accessing internal resources.

At this point, the IPSec tunnel goes down and comms are lost for the next 10 - 15 seconds. When comms are restored, ping results drop back down to 2 - 3ms.

I'm assuming this is a performance / load issue with the Cisco RV325 and it seems it is unable to cope with the load - essentially causing all sorts of performance issues and seems to reset its connections.

I was wondering if this sounds accurate ? Is there anything else I can look for ?

All ports on the Cisco router are configured for gigabit speed so I dont think its a port configuration issue.



No comments:

Post a Comment