Cisco Support Community
Showing results for 
Search instead for 
Did you mean: 
Community Member

Performance on with IPsec & Windows Shares

Pix 506E to Pix 506E.

I have one serveur running Windows share and Ftp from one side of the one IPsec tunnel.

I have a Windows 2000 stations on the other tunnel side.

When I connect the serveur with share like that \\X.X.X.X\Share the directory browsing it is slow (very), it severals second to change directory.

When I connect the serveur with ftp like that ftp://X.X.X.X/Share the browsing it is ok !!!

If someone has an idea, I would appreciate.


Community Member

Re: Performance on with IPsec & Windows Shares

Typically, FTP is the preferred method for many since it is considered faster than HTTP. Some difference in time taken by the two can be expected. However, this should not be too much. What might be happening is that your configuration might be letting your ftp traffic through unencrypted. However, the best bet is to check the server response itself. Try bypassing the firewall for these two types of traffic and see if you still observe the difference in response times. This will help you pinpoint where the problem lies.

VIP Purple

Re: Performance on with IPsec & Windows Shares

SMB (aka windows file sharing) is *hyper* senstive to the RTT. For example, doubling the RTT can quadruple the response time. VPN's, running over the Internet, have a considerably higher RTT than compared to your local LAN.

FTP does not suffer this problem.

One suggestion I could make is to do a search on Google, and download a copy of "DrTCP". This lets you adjust your window size. Crank it right up to say 64KB. Do this on both the server and the workstation.

This will help reduce the effect of slow transfers.

CreatePlease to create content