Geekzone: technology news, blogs, forums
Guest
Welcome Guest.
You haven't logged in yet. If you don't have an account you can register now.




2880 posts

Uber Geek
+1 received by user: 1503

Subscriber

Topic # 224037 30-Oct-2017 11:58
Send private message quote this post

This isn't really covered by @michaelmurfy  's excellent router guide, so throwing this open for the masses.

 

Currently in the middle of getting Gigabit UFB into several sites for work, and once we have those connections in place we're going to want start using them. Finding a nice business grade router that can handle those UFB connections is easy enough, but we're really wanting to be able to get close to line speed across an IPSec VPN as well. That seems to be a bit more difficult.. What can people suggest that's going to let me get at least 7-800mbps sustained IPSec VPN throughput for a reasonable price? 





Information wants to be free. The Net interprets censorship as damage and routes around it.

 

Thinking about signing up to BigPipe? Get $20 credit with my referral link.


View this topic in a long page with up to 500 replies per page Create new topic
 1 | 2
2080 posts

Uber Geek
+1 received by user: 621

Subscriber

  Reply # 1892537 30-Oct-2017 12:16
One person supports this post
Send private message quote this post

Define reasonable? A quick look at Cisco, Meraki and Juniper you would be looking at between 10 and 20k per device. That sort of VPN processing power comes at a cost! 


5095 posts

Uber Geek
+1 received by user: 2123

Trusted
Subscriber

  Reply # 1892549 30-Oct-2017 12:28
One person supports this post
Send private message quote this post

This one does up to 400Mbps: http://www.draytek.com.au/products/broadband-routers/vigor2960/ 

 

This one does up to 800Mbps but not locally available (probably could get on special order through SnapperNet): http://www.draytek.com.au/products/broadband-routers/vigor3900/ 

 

 





Chorus has spent $1.4 billion on making their xDSL broadband network faster. If your still stuck on ADSL or VDSL, why not spend from $150 on a master filter install to make sure you are getting the most out of your connection?
I install - Naked DSL, DSL Master Splitters, VoIP, data cabling and general computer support for home and small business.
Rural Broadband RBI installer for Ultimate Broadband and Full Flavour

 

Need help in Auckland, Waikato or BoP? Click my email button, or email me direct: [my user name] at geekzonemail dot com


 
 
 
 


2080 posts

Uber Geek
+1 received by user: 621

Subscriber

  Reply # 1892551 30-Oct-2017 12:32
One person supports this post
Send private message quote this post

Considered building out PFsense boxes?




2880 posts

Uber Geek
+1 received by user: 1503

Subscriber

  Reply # 1892559 30-Oct-2017 12:44
Send private message quote this post

lxsw20:

 

Define reasonable? A quick look at Cisco, Meraki and Juniper you would be looking at between 10 and 20k per device. That sort of VPN processing power comes at a cost! 

 

 

1-3K

 

Fortigate 60E/80E/100E series are looking to be the prime candidates from what I can see, they respectively do 2/2.5/4gbps IPSec VPN throughput.

 

 





Information wants to be free. The Net interprets censorship as damage and routes around it.

 

Thinking about signing up to BigPipe? Get $20 credit with my referral link.




2880 posts

Uber Geek
+1 received by user: 1503

Subscriber

  Reply # 1892563 30-Oct-2017 12:45
Send private message quote this post

lxsw20:

 

Considered building out PFsense boxes?

 

 

For a bunch of reasons it's not really a viable option.





Information wants to be free. The Net interprets censorship as damage and routes around it.

 

Thinking about signing up to BigPipe? Get $20 credit with my referral link.


38 posts

Geek
+1 received by user: 3


  Reply # 1893174 31-Oct-2017 14:48
Send private message quote this post

coffeebaron:

 

This one does up to 400Mbps: http://www.draytek.com.au/products/broadband-routers/vigor2960/ 

 

This one does up to 800Mbps but not locally available (probably could get on special order through SnapperNet): http://www.draytek.com.au/products/broadband-routers/vigor3900/ 

 

 

 

 

For VPN:

 

  • 2960 may get 200 Mbps, not more
  • 3900 may get 600 Mbps, not more

The following chart has been "accurate" for the 2760.

 

http://www.draytek.co.uk/products/comparison

 

I have tested the 2760 (Spirent TestCenter: WAN-LAN, no VPN for that one) and it could only muster 150 Mbps with 1500-byte frames. At 64B, it was less than 7 Mbps. So have confirmed that the figures in that chart are best-case scenarios.

 

This put me off Drayteks for routers, though still using the DV130 for VDSL. As stable as they are, thoughput is not where I would want them to be.

 

 

 

 

 

 

 

 


dt

195 posts

Master Geek
+1 received by user: 23

Subscriber

  Reply # 1893197 31-Oct-2017 15:14
Send private message quote this post

Lias:

 

 For a bunch of reasons it's not really a viable option.

 

 

 

 

Is one of the reasons support? if it is you can buy supported pfsense devices, their specs are huge in comparison to other vendors and they're really hard to compete with on price vs performance. 

 

 

 

 https://www.netgate.com/solutions/pfsense/#on-premises

 

 

 

edit: link :) 


5095 posts

Uber Geek
+1 received by user: 2123

Trusted
Subscriber

  Reply # 1893203 31-Oct-2017 15:21
Send private message quote this post

@nitro thanks for the info. I know the Draytek 2860 series top out at approx. 400Mbps WAN-LAN, but also depends on what firewall / QoS / hardware acceleration it's doing. These are still very good routers for small business for the feature set they have.





Chorus has spent $1.4 billion on making their xDSL broadband network faster. If your still stuck on ADSL or VDSL, why not spend from $150 on a master filter install to make sure you are getting the most out of your connection?
I install - Naked DSL, DSL Master Splitters, VoIP, data cabling and general computer support for home and small business.
Rural Broadband RBI installer for Ultimate Broadband and Full Flavour

 

Need help in Auckland, Waikato or BoP? Click my email button, or email me direct: [my user name] at geekzonemail dot com


38 posts

Geek
+1 received by user: 3


  Reply # 1893205 31-Oct-2017 15:25
Send private message quote this post

@coffeebaron, agree. For small business users, the Drayteks pull their weight in price/performance. Not too long ago 200 Mbps VPN would have been a lot. These days, there are different requirements, such as the OPs. I'd be interested to see what they/he goes with, actually.

 

 

 

 

 

 


102 posts

Master Geek
+1 received by user: 28


  Reply # 1893207 31-Oct-2017 15:38
Send private message quote this post

You could look at a Ubiquiti Edgerouter Pro. Looks like people have got around 400 - 500 Mbps IPSec traffic through them. See link

https://community.ubnt.com/t5/EdgeMAX/ERL-Performance-Testing-with-IPSec-VPN/m-p/1053799/highlight/true#M44593

 

 

 

I know it's not quite as much as you were wanting, but for the money (around $700 each) they could be hard to beat.

Edit - Just had a look, the price/performance (just looking at IPSec traffic) is around the same as the Vigor2960. 


1800 posts

Uber Geek
+1 received by user: 263

Subscriber

  Reply # 1893216 31-Oct-2017 15:48
One person supports this post
Send private message quote this post

Mikrotik CCR1009-7G-1C-1S+





Ross

 

Spark FibreMAX using Mikrotik CCR1009-8G-1S-1S+

 


Speed Test


6924 posts

Uber Geek
+1 received by user: 3210

Moderator
Trusted
Lifetime subscriber

  Reply # 1893218 31-Oct-2017 15:53
Send private message quote this post

The Grandstream GWN7000 has hardware accelerated VPN and a newer CPU - I've found I could get 200Mbit out of it but an Ubiquiti USG was the weak link here as the Edgerouter Lite + USG top out at around 200Mbit. I had nothing to test its top speed.

 

Potentially the best value option here.





Michael Murphy | https://murfy.nz
Want to be with an epic ISP? Want $20 to join them too? Well, use this link to sign up to BigPipe!
The Router GuideCommunity UniFi Cloud Controller | Ubiquiti Edgerouter Tutorial


102 posts

Master Geek
+1 received by user: 28


  Reply # 1893223 31-Oct-2017 16:00
One person supports this post
Send private message quote this post

Spyware:

 

Mikrotik CCR1009-7G-1C-1S+

 

 

 

 

That's fairly impressive for the money. 


 

Click to see full size

 

 


3219 posts

Uber Geek
+1 received by user: 1021

Subscriber

  Reply # 1893232 31-Oct-2017 16:24
Send private message quote this post

The small Mikrotik CCR will do that no problem.

 

Have to say though, wondering the use case? 


5095 posts

Uber Geek
+1 received by user: 2123

Trusted
Subscriber

  Reply # 1893234 31-Oct-2017 16:29
Send private message quote this post

chevrolux:

 

The small Mikrotik CCR will do that no problem.

 

Have to say though, wondering the use case? 

 

 

Inter office file sharing from NAS / server would be one suitable use case.

 

 





Chorus has spent $1.4 billion on making their xDSL broadband network faster. If your still stuck on ADSL or VDSL, why not spend from $150 on a master filter install to make sure you are getting the most out of your connection?
I install - Naked DSL, DSL Master Splitters, VoIP, data cabling and general computer support for home and small business.
Rural Broadband RBI installer for Ultimate Broadband and Full Flavour

 

Need help in Auckland, Waikato or BoP? Click my email button, or email me direct: [my user name] at geekzonemail dot com


 1 | 2
View this topic in a long page with up to 500 replies per page Create new topic



Twitter »

Follow us to receive Twitter updates when new discussions are posted in our forums:



Follow us to receive Twitter updates when news items and blogs are posted in our frontpage:



Follow us to receive Twitter updates when tech item prices are listed in our price comparison site:





News »

$3.74 million for new electric vehicles in New Zealand
Posted 17-Jan-2018 11:27


Nova 2i: Value, not excitement from Huawei
Posted 17-Jan-2018 09:02


Less news in Facebook News Feed revamp
Posted 15-Jan-2018 13:15


Australian Government contract awarded to Datacom Connect
Posted 11-Jan-2018 08:37


Why New Zealand needs a chief technology officer
Posted 6-Jan-2018 13:59


Amazon release Silk Browser and Firefox for Fire TV
Posted 21-Dec-2017 13:42


New Chief Technology Officer role created
Posted 19-Dec-2017 22:18


All I want for Christmas is a new EV
Posted 19-Dec-2017 19:54


How clever is this: AI will create 2.3 million jobs by 2020
Posted 19-Dec-2017 19:52


NOW to deploy SD-WAN to regional councils
Posted 19-Dec-2017 19:46


Mobile market competition issues ComCom should watch
Posted 18-Dec-2017 10:52


New Zealand government to create digital advisory group
Posted 16-Dec-2017 08:47


Australia datum changes means whole country moving 1.8 metres north-east
Posted 16-Dec-2017 08:39


UAV Traffic Management Trial launching today in New Zealand
Posted 12-Dec-2017 16:06


UFB connections pass 460,000
Posted 11-Dec-2017 11:26



Geekzone Live »

Try automatic live updates from Geekzone directly in your browser, without refreshing the page, with Geekzone Live now.



Are you subscribed to our RSS feed? You can download the latest headlines and summaries from our stories directly to your computer or smartphone by using a feed reader.

Alternatively, you can receive a daily email with Geekzone updates.