IPsec or OpenVPN for pfSense Site‑to‑Site Tunnels When CPU Is Limited and NAT Traversal Is Required
26.5K reputation · 05 Mar 2023, 10:57 UTC
Goal: Select a site‑to‑site VPN mechanism for two pfSense 2.7.x firewalls that must operate on a CPU with limited AES‑NI support while also needing to traverse existing NAT devices without manual port forwarding.
IPsec benefits from hardware‑accelerated encryption, reducing per‑Mbps CPU load, but its default configuration struggles with symmetric NAT and often requires static port forwards or NAT‑T; OpenVPN runs in user space, consumes more CPU per Mbps, yet its TLS‑based design works through most NATs and offers flexible username/password authentication.
Uncertainty: Under heavy traffic, the pfSense state table timeout values may differ between the ipsec and openvpn processes, potentially affecting connection stability for long‑lived flows.
- Does enabling NAT‑T on IPsec sufficiently mitigate NAT traversal issues without sacrificing its CPU advantage on modest hardware?
- How do the default state table timeout settings for ipsec versus openvpn change when the firewall approaches CPU saturation, and which is more likely to cause premature state expiration?
- In a scenario where CPU usage exceeds 70 %, which VPN type maintains lower latency for real‑time traffic while keeping state table churn minimal?
1 answer
1 question comment
Use comments to ask for clarification. Post a solution as an answer.
26,525 reputation · 05 Mar 2023, 17:29 UTC
While the CPU efficiency of kernel-level IPsec is a major advantage, a critical practical detail for limited hardware is the handling of MTU (Maximum Transmission Unit) and fragmentation. When using IPsec with NAT-T, the additional UDP encapsulation increases packet overhead, which can lead to fragmentation if the MSS (Maximum Segment Size) is not correctly clamped.
On CPU-constrained pfSense devices, packet fragmentation is expensive because the CPU must spend cycles reassembling packets before decryption. To maintain the performance gains of AES-NI, it is recommended to:
- Configure
MSS Clampingon the VPN interfaces to ensure TCP segments fit within the tunnel overhead. - Verify that the
MTUis lowered (typically to 1400 or lower) to prevent the NAT device or the pfSense kernel from fragmenting packets.
Without these adjustments, a CPU that handles 100Mbps of clean IPsec traffic may spike to 70%+ usage simply due to the overhead of fragment reassembly, potentially negating the architectural advantage over OpenVPN.