Community discussions

MikroTik App
 
bedior
newbie
Topic Author
Posts: 41
Joined: Sat Jan 31, 2015 5:09 pm

What hardware select for VPN

Sun Oct 16, 2016 9:09 am

Hello.
Currently I'am using VPN as client on Mikrotik RB2011UiAS-2HnD-IN, it's giving me speed 23 mbit/s downloading and 20 mbit/s uploading on old firmware, new firmware give 16/20. My WAN give 30/100. If i connect to VPN by Windows client, it give 30/80 mbit. I think to replace it with EdgeRouter Lite or Mikrotik RB850Gx2. There are equal CPU frequency/number of cores, but maybe anybody has compared they performance?
What maximum speed I can get on L2TP IPsec with AES-256 encryption on RB850Gx2? What router you can recommend for home using with hardware acceleration and more powerful CPU?
 
mleonidov
just joined
Posts: 4
Joined: Sun Oct 16, 2016 10:21 am

Re: What hardware select for VPN

Sun Oct 16, 2016 10:23 am

EdgeRouter Lite
 
Unic
newbie
Posts: 48
Joined: Thu Jun 11, 2015 3:51 pm

Re: What hardware select for VPN

Sun Oct 16, 2016 2:11 pm

Maybe you can try the new hex with RB750Gr3. It has Hardwarenecryption and should encrypt aes256 faster than your connection speed. But i have not tested it.

But keep in mind that you cant have more than one vpn user behind the same wanIP if you are using L2TP/IPSec.
 
User avatar
колбаскин
newbie
Posts: 40
Joined: Tue Mar 29, 2016 6:36 pm
Location: Ukraine Zaporozhye
Contact:

Re: What hardware select for VPN

Sun Oct 16, 2016 2:48 pm

I have RB850x2 but speed of upload VPN l2tp+ipsec aes256 = 20megabit/sec., and the client of Windows10 = 80 megabits/sec.
The processor isn't loaded also for 50%
Mikrotik just strongly cuts speed.
Technical support doesn't pay attention to it.
 
bedior
newbie
Topic Author
Posts: 41
Joined: Sat Jan 31, 2015 5:09 pm

Re: What hardware select for VPN

Sun Oct 16, 2016 2:52 pm

RB750Gr3 is more powerful than RB850Gx2 and EdgeRouter Lite? If i found correctly, RB750Gr3 is equal EdgeRouter X? Which will be faster?
 
User avatar
mrz
MikroTik Support
MikroTik Support
Posts: 7053
Joined: Wed Feb 07, 2007 12:45 pm
Location: Latvia
Contact:

Re: What hardware select for VPN

Mon Oct 17, 2016 2:26 pm

RB850x2 with HW encryption can encrypt/decrypt up to 500Mbps with 1400byte packets
new hex RB750Gr3 can encrypt/decrypt up to 470Mbps with 1400byte packets
 
User avatar
колбаскин
newbie
Posts: 40
Joined: Tue Mar 29, 2016 6:36 pm
Location: Ukraine Zaporozhye
Contact:

Re: What hardware select for VPN

Mon Oct 17, 2016 3:17 pm

RB850x2 with HW encryption can encrypt/decrypt up to 500Mbps with 1400byte packets
new hex RB750Gr3 can encrypt/decrypt up to 470Mbps with 1400byte packets
Why such difference between Mikrotik and VPN the client in Windows10 on upload to the same server?
Settings are identical. Mikrotik cuts speed almost by 4 times.
Почему такая разница в скорости между RB850x2 и VPN клиентом в Windows10 на аплоад до одного и того же сервера?
Настройки идентичные. Mikrotik режет скорость почти в 4 раза.
 
psannz
Member Candidate
Member Candidate
Posts: 128
Joined: Mon Nov 09, 2015 3:52 pm
Location: Renningen, Germany

Re: What hardware select for VPN

Mon Oct 17, 2016 3:19 pm

l2tp+ipsec aes256
Which AES algorithm did you choose? CBC, CTR or GCM?

Switching from CBC to CTR always got me a hefty performance boost.
 
User avatar
колбаскин
newbie
Posts: 40
Joined: Tue Mar 29, 2016 6:36 pm
Location: Ukraine Zaporozhye
Contact:

Re: What hardware select for VPN

Mon Oct 17, 2016 3:22 pm

Image
 
psannz
Member Candidate
Member Candidate
Posts: 128
Joined: Mon Nov 09, 2015 3:52 pm
Location: Renningen, Germany

Re: What hardware select for VPN

Mon Oct 17, 2016 3:25 pm

Image
Switch from CBC to CTR.

HW acceleration seems bugged atm, handling ecryption via software is better atm :(
 
User avatar
колбаскин
newbie
Posts: 40
Joined: Tue Mar 29, 2016 6:36 pm
Location: Ukraine Zaporozhye
Contact:

Re: What hardware select for VPN

Mon Oct 17, 2016 3:29 pm

Image
Switch from CBC to CTR.

HW acceleration seems bugged atm, handling ecryption via software is better atm :(
How do this?
Thanks
 
User avatar
колбаскин
newbie
Posts: 40
Joined: Tue Mar 29, 2016 6:36 pm
Location: Ukraine Zaporozhye
Contact:

Re: What hardware select for VPN

Mon Oct 17, 2016 3:30 pm

Switch from CBC to CTR.
HW acceleration seems bugged atm, handling ecryption via software is better atm :(
How do this?
I use Mikrotik as the client and as the server
Thanks
 
User avatar
колбаскин
newbie
Posts: 40
Joined: Tue Mar 29, 2016 6:36 pm
Location: Ukraine Zaporozhye
Contact:

Re: What hardware select for VPN

Mon Oct 17, 2016 3:41 pm

SoftEther VPN not work with CTR
RC4-MD5, RC4-SHA, AES128-SHA, AES256-SHA, DES-CBC-SHA and DES-CBC3-SHA

It turns out at all a problem with speed, and Mikrotik simply deceives the clients in speed
 
pe1chl
Forum Guru
Forum Guru
Posts: 10223
Joined: Mon Jun 08, 2015 12:09 pm

Re: What hardware select for VPN

Mon Oct 17, 2016 4:16 pm

It turns out at all a problem with speed, and Mikrotik simply deceives the clients in speed
The problem is at the Windows side. The MikroTik routers with hardware acceleration on multicore processors
are really fast, but they re-order the packets when the link is loaded (multi cores operate in parallel) and
the Windows OS does not handle this well.
 
User avatar
колбаскин
newbie
Posts: 40
Joined: Tue Mar 29, 2016 6:36 pm
Location: Ukraine Zaporozhye
Contact:

Re: What hardware select for VPN

Mon Oct 17, 2016 4:33 pm

It turns out at all a problem with speed, and Mikrotik simply deceives the clients in speed
The problem is at the Windows side. The MikroTik routers with hardware acceleration on multicore processors
are really fast, but they re-order the packets when the link is loaded (multi cores operate in parallel) and
the Windows OS does not handle this well.
You want to tell that the client of VPN in Windows 10 doesn't cipher a traffic or he is worse because by 4 times quicker than Mikrotik?
Вы хотите сказать что клиент VPN в Windows 10 не шифрует трафик или он хуже потому что в 4 раза быстрее чем Mikrotik?
 
bedior
newbie
Topic Author
Posts: 41
Joined: Sat Jan 31, 2015 5:09 pm

Re: What hardware select for VPN

Mon Oct 17, 2016 4:37 pm

Maybe speed degradation after firmware updates, is Windows or ISP problem too? :)))
 
pe1chl
Forum Guru
Forum Guru
Posts: 10223
Joined: Mon Jun 08, 2015 12:09 pm

Re: What hardware select for VPN

Mon Oct 17, 2016 4:43 pm

It is quite regular for routers that on firmware updates that add more features, the top speed decreases because CPU overhead for the new features has increased.
This happens in all routers, probably not for every upgrade.
The solution of using -CTR encryption is based on the fact that this encryption is not hardware accelerated and so the re-ordering does not occur, and Windows handles it better.
It would be best when MikroTik adds a checkmark where you can select software encryption for those codes that are now handled in hardware, until some solution has been found to avoid the re-ordering problem.
But best would be to file a bug report at Microsoft against their TCP implementation. It is not handling re-ordering well.
 
bedior
newbie
Topic Author
Posts: 41
Joined: Sat Jan 31, 2015 5:09 pm

Re: What hardware select for VPN

Mon Oct 17, 2016 5:42 pm

It is quite regular for routers that on firmware updates that add more features, the top speed decreases because CPU overhead for the new features has increased.
This happens in all routers, probably not for every upgrade.
Of course, if new features is used. But why speed decrease, when new features is disabled? I can understand, that new features need more hardware power, but when in new firmware CPU idle with 40%, and speed is down I can't understand.
 
alexjhart
Member Candidate
Member Candidate
Posts: 197
Joined: Thu Jan 20, 2011 8:03 pm

Re: What hardware select for VPN

Mon Oct 17, 2016 6:42 pm

It turns out at all a problem with speed, and Mikrotik simply deceives the clients in speed
The problem is at the Windows side. The MikroTik routers with hardware acceleration on multicore processors
are really fast, but they re-order the packets when the link is loaded (multi cores operate in parallel) and
the Windows OS does not handle this well.
I also saw issues outside of Windows. re-ordering is a problem when it happens at the levels Mikrotik does it at. Some applications are better at dealing with this, but bottomline they need to fix the ordering problem, which they have confirmed they are working on. More on this issue: http://forum.mikrotik.com/viewtopic.php ... 5&p=563395
 
Unic
newbie
Posts: 48
Joined: Thu Jun 11, 2015 3:51 pm

Re: What hardware select for VPN

Tue Oct 18, 2016 12:18 am

RB850x2 with HW encryption can encrypt/decrypt up to 500Mbps with 1400byte packets
new hex RB750Gr3 can encrypt/decrypt up to 470Mbps with 1400byte packets

Where on the mikrotik webpage i can get the informations which device has hardware encryption and which encryptionmethods are supported ? I havent seen any information on the productpage of the RB850x2 f.e..

Its soo hard to find the right device for a special purpose when informations are hidden.
 
alexjhart
Member Candidate
Member Candidate
Posts: 197
Joined: Thu Jan 20, 2011 8:03 pm

Re: What hardware select for VPN

Tue Oct 18, 2016 12:33 am

RB850x2 with HW encryption can encrypt/decrypt up to 500Mbps with 1400byte packets
new hex RB750Gr3 can encrypt/decrypt up to 470Mbps with 1400byte packets

Where on the mikrotik webpage i can get the informations which device has hardware encryption and which encryptionmethods are supported ? I havent seen any information on the productpage of the RB850x2 f.e..

Its soo hard to find the right device for a special purpose when informations are hidden.
This is probably the most up-to-date place http://wiki.mikrotik.com/wiki/Manual:IP ... encryption
 
bedior
newbie
Topic Author
Posts: 41
Joined: Sat Jan 31, 2015 5:09 pm

Re: What hardware select for VPN

Tue Oct 18, 2016 3:38 pm

Let's discuss routers, not nations. A lot of people have troubles with Mikrotik hardware, some things works bad, and I, and maybe колбаскин, wants that our devices works as described. Mikrotik must be interested with this too.
 
bedior
newbie
Topic Author
Posts: 41
Joined: Sat Jan 31, 2015 5:09 pm

Re: What hardware select for VPN

Tue Oct 18, 2016 7:00 pm

So, anybody buy RB750Gr3? Have you tried IPsec?
 
th0massin0
Member Candidate
Member Candidate
Posts: 156
Joined: Sun May 11, 2014 4:16 am
Location: Poland

Re: What hardware select for VPN

Fri Oct 21, 2016 5:38 pm

Is there any RouterBoard with IPSEC performance (like RB750GR3 - HEX v3) and combined with wlan in one device?
 
godlike
just joined
Posts: 21
Joined: Mon Jul 15, 2013 6:41 pm

Re: What hardware select for VPN

Fri Oct 21, 2016 5:43 pm

What about RB750Gr3 + http://wiki.mikrotik.com/wiki/Supported ... less_cards ?

P.S. Sorry, this will not work:
Note: RouterOS v6 does not support any USB Wi-Fi adapter
Last edited by godlike on Fri Oct 21, 2016 5:55 pm, edited 1 time in total.
 
User avatar
колбаскин
newbie
Posts: 40
Joined: Tue Mar 29, 2016 6:36 pm
Location: Ukraine Zaporozhye
Contact:

Re: What hardware select for VPN

Fri Oct 21, 2016 5:52 pm

All characteristics of Mikrotik are strongly overestimated. It is a marketing
RB750Gr3
2) How could I obtain promised 450Mbit of IPSec throughput? Currently I have only about 130Mbit.
http://forum.mikrotik.com/viewtopic.php?f=3&t=113724

bedior made request in technical support that after the connection defined ON speed l2tp+ipsec strongly has fallen
 
compuguy
just joined
Posts: 4
Joined: Sun Oct 23, 2016 2:34 am
Location: USA

Re: What hardware select for VPN

Sun Oct 23, 2016 6:30 am

It turns out at all a problem with speed, and Mikrotik simply deceives the clients in speed
The problem is at the Windows side. The MikroTik routers with hardware acceleration on multicore processors
are really fast, but they re-order the packets when the link is loaded (multi cores operate in parallel) and
the Windows OS does not handle this well.
I also saw issues outside of Windows. re-ordering is a problem when it happens at the levels Mikrotik does it at. Some applications are better at dealing with this, but bottomline they need to fix the ordering problem, which they have confirmed they are working on. More on this issue: http://forum.mikrotik.com/viewtopic.php ... 5&p=563395
Based on that thread, the reordering issue seems to be a CCR issue. I'm doubting that the rb1100ahx2 has this issue?

Who is online

Users browsing this forum: No registered users and 62 guests