How to quicly test theoretical OpenVPN throughput

Triggered by a customer who had problems getting enough speed through an IPsec site-to-site VPN tunnel between FortiGate firewalls I decided to test different encryption/hashing algorithms to verify the network throughput.I used two FortiWiFi 90D firewalls that have an official IPsec VPN throughput of

With the test configuration changed from multiple TCP sessions to a single TCP session, only one CPU core reaches maximum capacity on the RAS Gateway VMs. The maximum throughput on the GRE tunnel is between 400-500 Mbps. The following illustration depicts CPU …



AES-NI is Intel's dedicated instruction set, which significantly improves the speed of Encrypt-Decrypt actions and allows one to increase VPN throughput (Site-to-Site, Remote Access and Mobile Access). The general speed of the system depends on additional parameters.