Pantek Library
Hosting Provided By
CybrHost
High Speed Hosting

Re: [Users] Performance freeswan

From: Alex Pankratov <alex(at)cipherica.com>
Date: Sun Mar 23 2003 - 19:38:19 EST

My money is on the excessive packet fragmentation.

If you run IPsec in tunnel mode, it's normally a good idea to have DF (dont fragment) flag copied from the plaintext IP header to the the one prepended by ESP. This allows Path MTU discovery algorithm to function correctly and ensures that packet size does not exceed media MTU after the encryption.

If DF flag is not copied, but reset instead, the traffic will still flow, but excessive fragmentation will degrade the performance quite a bit.

IPsec clients (including IIRC Sentinel) sometimes have an advanced option controlling DF-copying behaviour. It is quite useful to troubleshoot scenarios with buggy *cough*Linksys *cough* routers.

I'd suggested to start with tcpdump'ing the traffic and checking if there are more IP fragments than usual.

Alternately, you can try configuring built-in XP IPsec agent and see if performance improves. If it does, then Sentinel is obviously at fault. Also check that Sentinel is not configured to do any sort of excessive logging or auditing.

/alex

Do you need help?X

G.T. van Amersfoort wrote:
> Hello,



Users mailing list
Users@lists.freeswan.org
http://lists.freeswan.org/mailman/listinfo/users Received on Sun Mar 23 21:30:18 2003

This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 13:01:02 EDT


Contact Us  Legal Notices  Order Services Online 
Pantek Home  Privacy Policy  IT news  Site Map  Pantek Library