Community discussions

MikroTik App
 
CuninganReset
Frequent Visitor
Frequent Visitor
Topic Author
Posts: 69
Joined: Mon May 02, 2016 7:49 pm
Location: Spain

SSTP over 1 Gbps link bad performance

Fri Jun 14, 2019 1:54 pm

Hello guys.

I have connected two CloudCore 1009 over a 1Gbps link using SSTP.

A bandwidth test between the CloudCores is around 840Mbps in TCP and 1 Gbps in UDP.

But when doing the bandwidth test over the SSTP tunnel I am getting 40 Mbps or little more and I do not know the reason.

Both CloudCores support hardware AES256 coding and the CPU are not high at all.

Any of you have suffered this issue before??
 
User avatar
sebastia
Forum Guru
Forum Guru
Posts: 1782
Joined: Tue Oct 12, 2010 3:23 am
Location: Antwerp, BE

Re: SSTP over 1 Gbps link bad performance

Fri Jun 14, 2019 2:10 pm

probably related to fragmentation, you'll need to adjust the MTU to max allowed by tunnel.
 
sindy
Forum Guru
Forum Guru
Posts: 10206
Joined: Mon Dec 04, 2017 9:19 pm

Re: SSTP over 1 Gbps link bad performance

Fri Jun 14, 2019 2:44 pm

Unless something has changed recently, only IPsec can make use of hardware encryption on Mikrotik.
 
r00t
Long time Member
Long time Member
Posts: 674
Joined: Tue Nov 28, 2017 2:14 am

Re: SSTP over 1 Gbps link bad performance

Sat Jun 15, 2019 3:34 pm

Also running tunnels over TCP is bad for performance and latency. Try IPSEC and results should be much better... hardware crypto offload will work and there will be no TCP to cause issues.
 
CuninganReset
Frequent Visitor
Frequent Visitor
Topic Author
Posts: 69
Joined: Mon May 02, 2016 7:49 pm
Location: Spain

Re: SSTP over 1 Gbps link bad performance

Wed Jun 19, 2019 5:43 pm

Unless something has changed recently, only IPsec can make use of hardware encryption on Mikrotik.
Opsss I expect the CloudCore 1009 to use the hardware crypto because the cypher is AES256 as in IPsec...

If I am wrong I need to redesign my solution because of this.

In the hardware crypto page, they state that CloudCore support AES256 hardware crypto but they do not specify that only using IPsec.

Who is online

Users browsing this forum: Amazon [Bot], iDaemon, jaclaz, pturmel, qwertykolea, woland and 229 guests