mcdouglas
This is a known issue on MT hardware routers with ipsec tunnels and high-latency link:viewtopic.php吗?t=146665#p769858
You must use a CHR - this software router do not have this issue.
你为什么需要一个通用处理器if you plan to execute only one function?ARM CPU, RB5009 level for shaping duty.
My advice - use a CHR.Hi.
We have 220ms R.T.T. between Malaysia and England.
Any tips for VPN passing SMB?
even when using CPU (AES-NI), speed reaches almost 30Gbps.the improvements in IPSEC performance are from ASIC Hardware Acceleration Built in the SOC
there is no General Purpose CORE, not ARM, not x86, not MIPS, no POWER PC, capable of this kind of IPSEC performance by their own
but what about routers with switch chip?None of them do.
x86 also have power-efficient cores:Arm cores are more power/heat friendly compared to intel CPUs.
create ipsec proposal sha1/aes-128 cbc and profile with DH Group: ecp256I have played around with various security settings on server with no luck.
YesIn the case where you thought it was limited to 14 hops, were the last 5 timeouts too?
Can you provide proof in the form of test results on a gigabit network? (gre+ipsec vs. pure ipsec tunnel mode, file copy throughput results and profile results)I exclusively use GRE/IPsec and I do not have that experience.
Yes, all hardware routers have same issue.However both 1036 and 2004 have the very same issue.
Try replacing hardware routers with CHR routers.how can I solve this issue?
No, VM have setting Video card - Total video memory = 4 MBThe hypervisor will also reserve some memory for video RAM.
Thanks, it helped!in case there is NAT between server and client: google "AssumeUDPEncapsulationContextOnSendRule"