Low speeds on Wireguard [ Brume 2 + Beryl AX ]

Hi all,

I've left my Brume 2 in a location with 1000down/1000up fiber and I'm currently seeing less than ideal speeds while connected over WG. My current location has 500/500 ( over cable ) and ~200/200 when connected to my beryl over 5GHz 160. The problem is, as soon as I turn on the VPN, speed drops to ~20-30down/~60up and latency goes to ~200. I understand the latency part, but why does the speed drop so much? I've tried playing with different MTU settings, but didn't achieve anything substantial. Any thoughts? Starting to blame hardware at this point. Happy to provide any config/info needed.

ISPs on both sides do not throttle WireGuard traffic. The setup is ISPs switch=>Beryl AX. Tests/speeds were measured on both WiFi and over cable ( cat6 , 3 different cables ).

Hi,

VPN speed low probably relates to these:

  1. Cross-border, cross-regional, cross-sea, and cross-operator VPN network.
    After so many network facilities, GL has no way of knowing where bottlenecks or limitations have arisen.
    There is also a priority relationship between operators of network facilities at all levels.
    For example, if ISP A and B both using the same submarine fiber (cross-sea) to reach another country or another place, so that depending on who (A or B) pays more, the who one will get the traffic response is prioritized, as well as taking up more bandwidth.

  2. There are some restrictions between cross-operator networks. For example, the US operator (ATT) and the Indian operator (TATA) have not signed an advanced partnership. ATT may not allow too high TATA traffic or rates to enter its network, occupying ATT itself. network resources

  3. Speedtest.net as is a public service website. Their speed test servers (i.e. nodes) are set up in large computer rooms and high-performance servers. They purchase the maximum bandwidth and maximum traffic of their servers from cloud server operators to ensure that the speed test is as high as possible.
    The traffic processing priority of large network services (like youtube.com, speedtest.net, tiktok.com, etc.) in the public network is much higher than the SME and family, because they pay much more for network maintenance than SME and family.
    Therefore, the speedtest node speed-rate cannot be regarded as the speed which access the VPN server of SME company/family, since the network resources and priority are not as good as public services like speedtest/google/etc.

Add:
If the VPN tunnel speed under 250Mbps, it has not reached the bottleneck of MT2500 (can use the command to check the CPU/memory usage in the SSH: top).
Moreover, MT2500 will not limit any network speed and will priority process the VPN packets with maximum CPU performance.

Advice:

  1. If India wants to get the better VPN speeds, consult the ISP to upgrade the WAN broadband of US company.

  2. Refer to public service like speedtest.net, which uses a cloud server with better network resources, establish your own VPN Server in the cloud.
    The MT2500 and MT3000 as the client, they connect to the VPN server, which is in the cloud and self-hosted, I assume the MT3000/MT2500 will get a better VPN speed.

You could reset to factory settings your mt3000 and setup a wg "server" there. Disable WiFi. Connect wan to internet.

Now connect your mt2500 wan to mt3000 lan. Configure mt2500 wg client to use mt3000 wg client.

Connect your test device to mt2500 and run speedtest, fast.com, speed.cloudflare.com or waveform’s buffer bloat test.

You should see 250-300 Mbps.

1 Like