Site2Site Flint 2 - Slower VPN - What am I doing wrong?

Hi All,

I am fairly new to Gli Net but fairly well versed with Unifi etc, made the jump for ease of setup and speed wireguad but running into some issues.

I have two officers. Site A hosts a Synology NAS with AD Server running and bunch of PC’s, I have Virgin Router Hub in Modem only mode connected to Gli Net Flint 2 MT6000. I am running this Flint as a Wireguard Server.

In Site B I have another Gli Net Flint 2 MT6000 connected also to a Virgin Hub which is in modem only modem. Therefore both Flints do all the routing, This flints connects via client to the office in Site A. The PC’s then logon and pull group policies off the NAS AD an shares etc.

The virgin media hubs are both on 350mps packages and without VPN I can see about 250 +280 mbps.

The issues I am having is that when I connect the VPN site to Site or new profile on individual PC’s I am only seeing 25mbps. This is slowing everything down at Site B.

I did abit of research online and people suggested to bring down the MTU which I did when creating a profile and lowest iv had is 1280 without any change. There is users online getting 100+ speeds on these Flints – Why is my set up slow and how can Increase the speed? I would be happy with anything 100mpbs +.

Can anyone help before I raise a support ticket?

I know I'd be pretty pissed off if I wasn't getting that ~100 Mbps difference.

Yup. 350 Mbps might be the down but what's the package's upload rate? That's the choke point. Site B's up is Site A's down & vice versa.

Thanks for getting back- The upload speed is advertised as 36mbps. I hit about 30 /32 direct.

I agree about the 100mpbs difference but after troubleshooting the solution was to say I am no longer in contract and that I can cancel as they cant improve the 100mb, its abit hit an miss as some days hit 300 /320 etc.

The issue I am having is client to client its about 25mpbs but when in site to site its crawls to about 10mbps. I cant see why, i did try change the MTU to 1380 in the config file but made no difference.

Any suggesitons?

How strange. WG is technically all peer-to-peer; it's the routing at the endpoints that makes it 'client/server', 'master/slave' or 'site-to-site.' You're not running 'VPN Cascading', are you? That a feature of the v4.7.x series; it puts a hit on the over all performance. I wouldn't be surprised if trying to use OVPN at the same time wouldn't do the same.

Firmware v4.8.x is much more flexible with routing options. GL calls is 'VPN composite policies' but you might know it better as policy based routing (PBR). I mention this because I don't see that I asked what f/w is being used.

To your question re: MTU: I can set my tunnels as low as 1280 & still hit the 'burst rates' my ISP allows (~20% over package). My now EOL'd Creta (launched 2017) can handle ~65 Mbps @ 1320 MTU on its single core 650 MHz SOC, 128 MB RAM, 100 MbE. It's only advertised to 50 Mbps over WG.

Off-topic: I know I would be pissed off if I wasn't getting that 2--4 Mbps difference in upload.