cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

New Full Fibre 1.6Gbps - Slow VPN Connections

Fogzter
Investigator
Investigator

Hi

I've just had my 1.6Gbps full fibre installed yesterday and without my VPN switched on I'm receiving the full 1.6 down and 115 up.  However when connecting  my Surfshark or Mullvad VPN using Wireguard protocal the speed drops to around 500Mbps.  I've tried deleting all my VPN connection on my Unifi router and recreating my key pairs etc as well I setting up different VPN servers but the speed is always the same.  I've also tried setting up OpenVPN, both TCP and UDP and these are even worse with speeds around 200Mpbs.

So my question is do EE perform some sort of throttling on VPN connections and is there a way around it?  If not then I'll need to cancel my contract as I'm still in my cooling off period and wondered if anyone has recomendations on whose services works best with VPN conntions?

Thanks

26 REPLIES 26

@Fogzter That makes a difference then now, looking like Unifi need to FW check the VPN server/client on there gateway. Does not take much to mess up a connection at all.

Fogzter
Investigator
Investigator

Thanks @JimM11 I've got a support ticket logged with them, so will let you know what they say.  Cheers

@Fogzter Pictures are all cleared now, VPN Off/On is as about expected with the latency and your Use 1500 MTU is off WAN settings which is helpful but would need to dig into unifi info if correct settings. No two routers are alike, what is good for one may be bad for the other.


@Fogzter wrote:

I never had this kind of slowness with Airband full fibre...


And what speed was your Airband connection provisioned at/how did it connect to the Internet? Perhaps it wasn't able to reach any bottleneck you might have?

Both PPPoE and running a VPN on the gateway are processor intensive activities and it's not unheard of for Unifi gear to struggle at higher speeds. Have you tried with IDS/IPS switched off? Have you checked to ensure the UCG is using hardware acceleration/offload?

That said, you might be fighting a losing battle if comments like this are anything to go by - https://www.reddit.com/r/Ubiquiti/comments/1kefc65/is_the_cloud_gateway_fiber_fast_enough_to_handle/

Hi @bobpullen I'll lokk into those settings but I'm really starting to think its a router limitation, as I've read that post you linked as well as this one:

https://ifeeltech.com/blog/ucg-fiber-review

Which states this:

Fogzter_0-1788525434322.png

Hardware acceleration is switched on and I've tried with and without IDS/IPS. The speeds with IPS disabled reach around 561Mbps compared to 551Mbps with it enabled.

But I think you're right, I might be in for a losing battle if I want the VPN always on with this router.  I'm wondering if I could use a GL.iNet Slate 7 Pro (GL-BE10000) or GL.iNet GL-MT3600BE Beryl 7 to connect my line and VPN and run my UFG behind that with all devices attached.

Waiting to hear back from Ubiquiti still to let me know their max throughput when connected to VPN.

I think you're right that this is just the limit of the router's wireguard client.

Before you buy something else, note that the UCG-Fiber has good hardware offloading for PPPoE. Many other routers (even high end ones) do not have this, which effectively limits their speeds to the 1 to 1.5 Gbps range, before any VPN overhead is taken into account. You might exchange one bottleneck for another.

 

@Fogzter - quick Google suggests those GL.iNet devices can do ~1Gbps. If I was going the GL.iNet route, I'd probably be considering the newly released Flint 4 (can do 1.5Gbps) with a view to replacing the Ubiquiti gateway outright (I don't like the idea of introducing extra points of failure). Although I think you've just missed the boat on earlybird pricing.

As it happens, I have a Beryl 7 myself that I'm currently in the process of packing into a suitcase for an overseas trip. I do use the  Wireguard client on it but can't attest to its performance as it tunnels back to an endpoint on my home network (so is limited by the Openreach upload).