Wireless Access

 View Only
last person joined: yesterday 

Access network design for branch, remote, outdoor, and campus locations with HPE Aruba Networking access points and mobility controllers.
Expand all | Collapse all

505Hr VPN throughput

This thread has been viewed 46 times
  • 1.  505Hr VPN throughput

    Posted May 10, 2021 01:02 PM
    The specs for a 505Hr is up to 500Mb for VPN encryption. We've purchased a dozen or so of the 505Hr in order to provide remote users with more then 100Mb of throughput back to our 7210 mobility controller. Speedtest have shown to be getting around 80-90 Mb of throughput. I do have a case open with Aruba, but no findings yet. We've tested with a host device directly connected to an open port on said 7210 on the subnet in questions and speedtest is well over 800 Mb (our ISPs are at 1Gb). We've also tested with a 505Hr port configured in bridge mode (whereas the traffic gets offloaded to the local ISP) and speedtests are close to 500 Mb (the amount provided by the ISP at test location). At same test location, the tunneled VPN data back to the 7210 isn't getting anywhere close to the 500Mbs. Does anyone have 505Hr in deployment in a mobility controller scenario and are you getting expected speed and if so, do you have to implement any special configuration?

    Regards,
    Tony Marques

    ------------------------------
    Tony Marques
    ------------------------------


  • 2.  RE: 505Hr VPN throughput

    EMPLOYEE
    Posted May 10, 2021 01:07 PM
    Is this wired or wireless?

    ------------------------------
    Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.
    ------------------------------



  • 3.  RE: 505Hr VPN throughput

    Posted May 10, 2021 01:15 PM
    Using port 1 for wired. Haven 't tried wireless yet, but was thinking of configuring a 505Hr with our corporate SSID and seeing if that is any different. Would you suggest/recommend I try that?

    ------------------------------
    Tony Marques
    ------------------------------



  • 4.  RE: 505Hr VPN throughput

    EMPLOYEE
    Posted May 10, 2021 03:48 PM
    Whatever vlan that wired device is on, enable bcmc-optimization on it, so that the wired devices doesn't have to compete with broadcasts for throughput.

    ------------------------------
    Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.
    ------------------------------



  • 5.  RE: 505Hr VPN throughput

    Posted May 11, 2021 02:41 AM
    We've had TAC case open for few months now and seems TAC does not have much idea what might cause it but we've randomly tried everything to see if something happens. It's Central managed but connecting to 7210. We've used both wireless and wired uplink, and even when using wireless uplink we can get decent speeds for bridge SSID but not when using tunneled SSID.

    So far most difference has been with different versions. For example newest 8.7.1.3 was really slow with wireless uplink, then again 8.8.0.0 is sort of OK. We only use those behind max 100Mbps uplinks but even with those we've seen something like 5-30Mbps speeds with some software versions. Then again 8.7.1.3 works with wired uplink...


  • 6.  RE: 505Hr VPN throughput

    Posted May 11, 2021 07:25 AM
    Hi pubjohndoe,

    Sorry to hear you've encountered the same issue and that TAC hasn't been able to resolve it. Seems like they need to go back to the developers to see how they were able to certify it for 500MBs. My TAC engineer ask that I change the RAP MTU to 1500 on the AP System Profile. I'm going to try that as well as cjoseph's recommendation. I'll keep the post updated with my findings.

    Regards,
    Tony Marques

    ------------------------------
    Tony Marques
    ------------------------------



  • 7.  RE: 505Hr VPN throughput

    Posted May 24, 2021 07:20 AM
    Hi pubjohndoe,

    This is my latest with my TAC case:

    We have reported the issue to Engineering with the logs/data collected so far, Engineering ticket number - AOS-221325.

    If any further logs/data is required, we would let you know.

    Will keep you informed on updates. Another update would be shared in couple of days.

    Regards,
    Tony Marques

    ------------------------------
    Tony Marques
    ------------------------------



  • 8.  RE: 505Hr VPN throughput

    Posted Jul 14, 2021 11:09 AM
    Been working with TAC and providing logs and more logs and latest is "Got an update from Engineering that, there were no traces for any anomalies on the logs collected during last remote session. Working on an plan to collect the required logs/data to find the root cause." How have you made out on your end?

    ------------------------------
    Tony Marques
    ------------------------------