IPSEC Speed degredation

Help!
Customer setup new PIX 506E and VPN tunnelling over a point-to-point 532A/XR5 radio link that is performing at blazing speeds, with Nstreme on, about 33Mbps. When passing traffic through the tunnel, directly connected to the MT, it just dies. Outside the tunnel its blazing. Radios have 35+db SNR, so no signal or wireless link error problems, 100/100 CCQ.

Any hints from anyone regarding where I can look or change a setting. I have enabled/disabled Nstreme, and changed the framing method every which way…

Thanks in advance for any hint on where I can look…

mtu related problem inside the tunnel?

that would be my guess too … MTU and things getting fragmented / clear dont fragment bit.

Also remember that the Cisco PIX506e is sloooooow.

Cleartext performance: 20 Mb/s
56-bit DES vpn: 20 Mb/s
168-bit DES (3DES) vpn: 16 Mb/s

And remember those are lab figures.
It’s only a 300 Mhz celeron.