Community discussions

 
CHSDE
just joined
Topic Author
Posts: 7
Joined: Tue Nov 11, 2014 11:49 am

RB2011 WAN interface not reaching full speed

Tue Jun 18, 2019 10:34 pm

Hi at all,

hoping that this is the correct forum for asking my question.
I've just upgraded my Internet connection from 50/5 MBit/s to 300/10 MBit/s.

My 2011 is connected to an AVM Fritzbox on ETH-5, LAN on ETH-1 both Gigabit-Ports.
The AVM Fritzbox as Gateway (cable internet) is showing 300/10 MBit/s reaching it.

But every speed test returning only 150 - 180 MBit. whilst upload rate is constant by 10 MBit/s

I looked around the forum and found some tipps, disabling LCD, set Queues to "ethernet-default" or check if Fast Track is activated.
But nothing helped yet.

Do you have any further ideas or may I show you my config somehow and you can help me investigate?
When I run speedtest I'm watching the green CPU-Box left from the padlock in top right corner of Winbox and it's very low which seems fine in my
opinion.

I would apreciate any help.

Thanks, Patrick

supplemental: my firmware is 6.44
 
User avatar
CZFan
Forum Guru
Forum Guru
Posts: 1435
Joined: Sun Oct 09, 2016 8:25 pm
Location: South Africa, Randburg
Contact:

Re: RB2011 WAN interface not reaching full speed

Wed Jun 19, 2019 2:15 am

Start by upgrading to 6.44.3, then post results of "export hide-sensitive" here (between source code bracket so, see menu bot tons above)
MTCNA, MTCTCE, MTCRE & MTCINE
 
CHSDE
just joined
Topic Author
Posts: 7
Joined: Tue Nov 11, 2014 11:49 am

Re: RB2011 WAN interface not reaching full speed

Thu Jun 20, 2019 1:33 pm

Hi, please excuse my late answer.
I was not informed about your post via mail notice.

I've done the upgrade with no success in speed behavior.
Please find my export down below.
set default-screen=stat-slideshow time-interval=hour
/lcd interface
set sfp1 disabled=yes
set ether2 disabled=yes
set ether3 disabled=yes
set ether4-Arlo disabled=yes
set ether6 disabled=yes
set ether7 disabled=yes
set ether8-HueBridge disabled=yes
set ether9-GWY-433 disabled=yes
set ether10 disabled=yes
/ppp secret
add name=Pxxxxxx profile=pptp-vpn service=pptp
add name=Sxxxxxx profile=pptp-vpn service=pptp
add name=Pxxxxxx profile=ovpn service=ovpn
add name=Sxxxxxx profile=ovpn service=ovpn
/system clock
set time-zone-name=Europe/Berlin
/system identity
set name=Pwall
/system lcd
set contrast=0 enabled=no port=parallel type=24x4
/system lcd page
set time disabled=yes display-time=5s
set resources disabled=yes display-time=5s
set uptime disabled=yes display-time=5s
set packets disabled=yes display-time=5s
set bits disabled=yes display-time=5s
set version disabled=yes display-time=5s
set identity disabled=yes display-time=5s
set bridge1 disabled=yes display-time=5s
set WLAN disabled=yes display-time=5s
set sfp1 disabled=yes display-time=5s
set eth01-LAN disabled=yes display-time=5s
set ether2 disabled=yes display-time=5s
set ether3 disabled=yes display-time=5s
set ether4-Arlo disabled=yes display-time=5s
set eth05-WAN disabled=yes display-time=5s
set ether6 disabled=yes display-time=5s
set ether7 disabled=yes display-time=5s
set ether8-HueBridge disabled=yes display-time=5s
set ether9-GWY-433 disabled=yes display-time=5s
set ether10 disabled=yes display-time=5s
/system logging
add action=Firewall topics=firewall
add action=vpn topics=ipsec
add action=vpn topics=pptp
add action=email topics=critical
add action=email topics=error
add action=email topics=warning
add action=vpn topics=ovpn
add action=email topics=system,error,critical
/system script
add dont-require-permissions=no name=WOL_on_VPN owner=admin policy=ftp,reboot,read,write,policy,test,password,sniff,sensitive source="tool wol interface=bridge1 mac=BC:5F:F4:EF:FD:77"
/tool e-mail
set address=smtp.xxxxx.de from=axxxxx@xxxxx.net start-tls=yes user=axxxxxx@xxxxx.net
/tool graphing interface
add interface=eth05-WAN
/tool romon port
add
/tool user-manager database
set db-path=user-manager
[admin@Pwall] > 
Greets Patrick
 
User avatar
CZFan
Forum Guru
Forum Guru
Posts: 1435
Joined: Sun Oct 09, 2016 8:25 pm
Location: South Africa, Randburg
Contact:

Re: RB2011 WAN interface not reaching full speed

Fri Jun 21, 2019 12:45 am

That does not look like the full export and without seeing firewall filter and mangle rules, it makes it difficult to make suggestions.

Read up on fasttrack, enable it and test again
MTCNA, MTCTCE, MTCRE & MTCINE
 
CHSDE
just joined
Topic Author
Posts: 7
Joined: Tue Nov 11, 2014 11:49 am

Re: RB2011 WAN interface not reaching full speed

Fri Jun 21, 2019 4:51 pm

Hi CZFan,

find my Firewall and NAT-config below:
/ip firewall address-list
add address=192.168.127.150-192.168.127.152 list="XBOX Live"
/ip firewall filter
add action=fasttrack-connection chain=forward connection-state=established,related
add action=accept chain=forward comment="accept established and related connections" connection-state=established,related log=yes
add action=accept chain=input comment=Ping log=yes protocol=icmp
add action=accept chain=input comment=FTP disabled=yes dst-port=21 in-interface=ether10 protocol=tcp
add action=log chain=input disabled=yes dst-port=21 in-interface=ether10 protocol=tcp
add action=accept chain=forward disabled=yes dst-address-list=Xbox dst-port=53,88,500,3074,3544,4500 in-interface=ether10 protocol=udp
add action=accept chain=forward disabled=yes dst-address-list=Xbox dst-port=53,80,3074 in-interface=ether10 protocol=tcp
add action=accept chain=input comment=Established connection-state=established
add action=accept chain=input comment=Related connection-state=related
add action=accept chain=input comment=OpenVPN dst-port=443 protocol=tcp
add action=accept chain=input comment="OpenVPN Ip-Pool Zugriff auf Gateway f\FCr DNS Aufl\F6sungen " dst-address=192.168.127.254 src-address=10.0.0.0/24
add action=log chain=input dst-port=443 log=yes log-prefix=OVPN protocol=tcp
add action=accept chain=input dst-address=192.168.127.254 log=yes log-prefix=ovpn protocol=tcp src-address=10.8.0.0/24
add action=accept chain=input comment=pptp-vpn disabled=yes dst-port=1723 protocol=tcp
add action=accept chain=input disabled=yes protocol=gre
add action=log chain=input dst-port=1723 protocol=tcp
add action=log chain=input protocol=gre
add action=accept chain=input comment="Zugang zum Router via VPN (TCP)" dst-address=192.168.127.254 protocol=tcp src-address=192.168.120.0/24
add action=accept chain=input comment="Zugang zum Router via VPN (UDP)" dst-address=192.168.127.254 protocol=udp src-address=192.168.120.0/24
add action=accept chain=input comment="Internes LAN (bridge1) darf auf den Router zugreifen" in-interface=bridge1
add action=log chain=input comment="Verbotenes Droppen"
add action=drop chain=input comment="Drop (Ports nach aussen schlie\DFen)"
add action=accept chain=forward comment="Beispiel zum Freigeben bestimmter Protokolle" disabled=yes dst-address=!192.168.127.0/24 dst-port=80,443 in-interface=bridge1 protocol=tcp
add action=drop chain=forward comment="Droppe alles, was nicht explizit freigegeben ist." disabled=yes
add action=drop chain=input disabled=yes dst-port=8080 in-interface=eth05-WAN protocol=tcp
/ip firewall nat
add action=masquerade chain=srcnat out-interface=eth05-WAN
add action=dst-nat chain=dstnat disabled=yes dst-port=53,88,500,3074,3544,4500 in-interface=ether10 log=yes log-prefix=XBOX_UDP protocol=udp to-addresses=192.168.127.150-192.168.127.152
add action=dst-nat chain=dstnat disabled=yes dst-port=53,80,3074 in-interface=ether10 log=yes log-prefix=XBOX_TCP protocol=tcp to-addresses=192.168.127.150-192.168.127.152
add action=dst-nat chain=dstnat disabled=yes dst-address=[##myStaticIp##] dst-address-list="XBOX Live" dst-port=53,88,500,3074,3544,4500 protocol=udp to-ports=3074
add action=dst-nat chain=dstnat dst-address=[##myStaticIp##] dst-port=3074 protocol=udp to-addresses=192.168.127.150 to-ports=3074
add action=redirect chain=dstnat disabled=yes dst-port=80 protocol=tcp to-ports=8080
 
User avatar
sebastia
Forum Guru
Forum Guru
Posts: 1790
Joined: Tue Oct 12, 2010 3:23 am
Location: Antwerp, BE

Re: RB2011 WAN interface not reaching full speed

Sat Jun 22, 2019 2:27 pm

Hi

Hint: next time export config with "/export hide-sensitive compact"

When I remove all the "disabled=yes", not much is left regarding forwarding traffic:
* single masq
* single dst-nat
* fasttrack / accept established / related

What is not there:
* routing: is fritz doing natting or bridging? If so are doing double natting then?
* interfaces / addresses used
* are you testing over vpn ?
* do you test with single or multi streams? See https://www.speedtest.net, at the bottom: Connections: Multi <> Single
* to properly monitor cpu usage, use /tool profile, the visual "icon" is insufficiently updated
 
User avatar
CZFan
Forum Guru
Forum Guru
Posts: 1435
Joined: Sun Oct 09, 2016 8:25 pm
Location: South Africa, Randburg
Contact:

Re: RB2011 WAN interface not reaching full speed

Sat Jun 22, 2019 10:11 pm

Hi

Hint: next time export config with "/export hide-sensitive compact"
i am sure "export" defaults to compact?
MTCNA, MTCTCE, MTCRE & MTCINE
 
CHSDE
just joined
Topic Author
Posts: 7
Joined: Tue Nov 11, 2014 11:49 am

Re: RB2011 WAN interface not reaching full speed

Sat Jun 29, 2019 11:36 pm

Hi, please excuse my late answer, I was on holidays ;-)

ok, find my answers within your quote.
What is not there:
* routing: is fritz doing natting or bridging? If so are doing double natting then?
--> It's natting. Bridging is disabled by providers branding.

* interfaces / addresses used
--> I don't know exactly what you mean.

* are you testing over vpn?
--> No.

* do you test with single or multi streams? See https://www.speedtest.net, at the bottom: Connections: Multi <> Single
--> the speedtest get's in multimode about 180 Mbit in singlemode about 170 Mbit.

* to properly monitor cpu usage, use /tool profile, the visual "icon" is insufficiently updated
--> While in "idlestate " cpu0 is about 3.0 - 4.0. While in speedtest max usage was at 30.
I've ran /export hide-sensitive compact and got something strange. Please look at this:
/interface bridge
add arp=proxy-arp name=bridge1
/interface ethernet
set [ find default-name=ether1 ] arp=proxy-arp name=eth01-LAN speed=100Mbps
set [ find default-name=ether5 ] name=eth05-WAN speed=100Mbps
set [ find default-name=ether2 ] speed=100Mbps
set [ find default-name=ether3 ] speed=100Mbps
set [ find default-name=ether4 ] name=ether4-Arlo speed=100Mbps
set [ find default-name=ether6 ] advertise=10M-half,10M-full,100M-half,100M-full,1000M-half,1000M-full
set [ find default-name=ether7 ] advertise=10M-half,10M-full,100M-half,100M-full,1000M-half,1000M-full
set [ find default-name=ether8 ] advertise=10M-half,10M-full,100M-half,100M-full,1000M-half,1000M-full name=ether8-HueBridge
set [ find default-name=ether9 ] advertise=10M-half,10M-full,100M-half,100M-full,1000M-half,1000M-full name=ether9-GWY-433
set [ find default-name=ether10 ] advertise=10M-half,10M-full,100M-half,100M-full,1000M-half,1000M-full
Why are my eth01-LAN and eth05-WAN running at 100 Mbps? They're connected to the Gigabit-Ports marked on the front-side of the RB2011.
My whole internal cabeling is managed by 1Gbit switches (Netgear GS 108)
And even when they're at 100 Mbps. How is can I get an internetspeed result of around 180 Mbps?

I'm really confused.
Patrick

...an additional annoation: When I look at Winbox' Interface/eth01-LAN or eth05-WAN/Status via the GUI both tell me a Rate of 1Gbps by Ful Duplex.
 
mkx
Forum Guru
Forum Guru
Posts: 3185
Joined: Thu Mar 03, 2016 10:23 pm

Re: RB2011 WAN interface not reaching full speed

Sun Jun 30, 2019 12:08 am

Command /export [compact] only shows settings that are different than default.

Ports in /interface ethernet have many settings, speed= is one of them. Setting of 100M used to be default in ROS prior to 6.42 (IIRC) and if your setup originates from earlier ROS, this value did not change with upgrade hence it appeared in export after upgrade to a more recent ROS.

However, there's a setting auto-negotiation with default value of yes which makes port to ignore most of other settings, including speed. Setting of advertise is one of observed settings though.

Actual running port speed is displayed by command /interface ethernet monitor <port name> once .
BR,
Metod
 
User avatar
sebastia
Forum Guru
Forum Guru
Posts: 1790
Joined: Tue Oct 12, 2010 3:23 am
Location: Antwerp, BE

Re: RB2011 WAN interface not reaching full speed

Mon Jul 01, 2019 9:01 pm

In your first post you mentioned
The AVM Fritzbox as Gateway (cable internet) is showing 300/10 MBit/s reaching it.
. Have you tried doring a speedtest directly attached to the fritz? What were the results?
 
CHSDE
just joined
Topic Author
Posts: 7
Joined: Tue Nov 11, 2014 11:49 am

Re: RB2011 WAN interface not reaching full speed

Tue Jul 02, 2019 2:00 am

Hi at all.
The problem is on providers side.
Tested now directly at the Fritzbox. Also only about 180 Mbps. Contacted my provider who confirmed the issue on his side, too.

I think we may keep this thread as solved.

Best regards and thanks for all the hints with those terminal commands.

Patrick

Who is online

Users browsing this forum: No registered users and 49 guests