I have the latest rolling release of VyOS running as both an SSTP and L2TP VPN endpoint. On the other side of the VPN I have a fileserver. When connected via L2TP, I can get 6-8MB/sec download speeds on file transfer, with SSTP its like 1-1.5MB/sec.
Everything else is the same, ISP/internet etc, network layout.
Is this to be expected?
I love SSTP + certbot, its an amazing VPN stack, given its so much more reliable than L2TP (and forever free certs), but this is a huge performance difference
Hello @kav, yes, this is a known issue with SSTP and big RTT (round-trip time). As an alternative you can try anyconnect implementation. ⚓ T2810 Docs for vpn anyconnect-server
Note: If you want I can build accel-ppp package with some improvements for you.
hey @Dmitry, thanks will check out anyconnect. Had not heard of that before, will see how that goes and report back! Im running these as VM’s in AWS and noticed the instance type also makes a difference to performance.
Just googled accel-ppp, looks interesting, does that offer even better performance? Assume it does not come with built in vyos CLI support?
PS; the RTT is only 20ms in this testing scenario.
Hello @kav, VyOS utilized accel-ppp as SSTP daemon. In the latest accel-ppp mater branch added a couple of improvements, but at first, need detailed testing these things. Do you want to test?
ah OK, trying to avoid third party client software and sticking with in-built Win10 VPN client.
Just updated/installed the package you provided for accel-ppp. Works well, immediately I can see SMB transfers are much more stable.
I can get 2-2.5MB/sec consistently on download and 1.5-2MB/sec on upload. Previously, especially on upload it would fluctuate wildly.
This is using t3 instances on AWS by the way which have enhanced networking. When I used t2, there seemed to be an issue with uploading SMB traffic - it would just get stuck.
Will keep testing and if all good will roll out to production for real users to try, thanks!
hmmm SSTP was fine during testing but L2TP actually had intermittent issues.
Starting an SMB transfer over the VPN would sometimes fail to initiate, then it would seem to stop moving any traffic at all, the gateway on the other side is not reachable etc. Reconnecting seemed to fix it.
Hi @Dmitry, yeah I did not have that setup. I set an mss of ‘1420’ on the IPSEC dummy interface, but the issue on L2TP still seems there. Once logged in, I did an SMB transfer, about a minute later all traffic stops flowing.
Is there an ideal mss number? Tried using some online calculators for it but didnt get far…
SSTP has been running great in production however.
Has the latest rolling release of VyOS got the latest version of accel-ppp? I checked their versions and they seem to match (1.12.0-95) but they have different build numbers.
PS; didnt get a chance to test L2TP with those IP tables changes you mentioned, the client has been mostly transition to SSTP. I’ll see if I can do some testing myself.