TZ 600 | Slow SSL VPN Speeds

Hello,

When a user connect to the SSL VPN using NetExtender, the download speed is only around 6-8 Mbps. The remote site is on a 100/100 fiber circuit, and as an example my home network is 500/500, and I still only get 8 Mbps.

I have tried the following.

  1. Disable Tunnel All Mode (I assumed regular web traffic would be fast since it’s supposed to route it outside of the VPN, but it’s still slow.)
  2. I ran some commands to disable NetAdapterRsc on my Wi-Fi adapter.
  3. I updated to the latest firmware and NetExtender client.
  4. The firewall is not licensed for security services, so there’s no overheaed there
  5. I verified Bandwidth Management is not enabled.

I am kind of at a loss here…anyone have any other ideas?

That’s the way it is. SonicWall will tell you if you want it to be faster to get an SMA.

Try disabling receive segment coalescing on the client computer and see if that makes any difference.

I’ve never been able to get more than about 10/10 mbps out of a Sonicwall SSLVPN. That plus the fact that Netextender likes to uninstall itself every several weeks or so has really pushed us away from them.

Yup, here to confirm… its just not fast, at all. Its just good enough to RDP into a PC on the other end.

SonicWall SSLVPN is slow. You’re getting the best you’re going to get most likely.

You can ty adjusting the MTU settings on the sonic wall WAN interface. I’ve had success with this especially in environments where more than one hop is over a VPN connection.

https://www.sonicwall.com/support/knowledge-base/set-mtu-in-vpn-environment-in-case-of-throughput-issues/170705131319789/

I was under the impression that Spilt tunnel mode would route my regular traffic over my regular routes internet and just the VPN traffic would be slow

i use gvc at home all day and get about 100/100 on my laptop. colo has a nsa3700, so it should be totally doable with your setup. i would contact support. also use winmtr to trace the connection, perhaps youre hitting a bad router somewhere.

Even with a SM1000 series, we get 30 Mbps max per user on SSLVPN. I mean it’s okay, but way slower than GVC…

In theory yes. But it will still send DNS and other requests to the inside VPN DNS server if you are using AD or Windows DHCP.

GVC runs in hardware ASIC on SonicWalls. SSL VPN is on the CPU the 6th gens are all caviums CPU. The 7th gen x86 CPUS have AES-NI which helps, and are a few magnitudes faster in raw power so I would imagine it would be better on a 7th gen.

I’d run more GVC except SonicWall still can’t figure out how to tie it in to MFA so that’s a deal breaker for me

Sonicwall cant but you can do MFA on GVC if you run a Radius server.

I did not know that. That’s awesome to know because we already use radius for wifi

Can confirm. We run this set up with MFA. I can get 100 Mbps no problem.