openVPN Traffic on remote interfaces

Hi, I’m working remote via Nethserver openVPN/Roadwarrior.
Still, I have a question about routing the payload.
I try to measure my download speed I get different loads on my local and the remote interface

I always thought all network traffic would be routed through my remote interface. Now it looks like only part of it is.

@capote

Hi Marko

Normally, only traffic to the remote site is routed via a VPN.

Traffic to the Internet is usually not - this would cause the same traffic to pass the via the remote Firewall / OpenVPN Gateway twice…

This is an option which needs to be set seperately, usually on the VPN client, but can be mandated and preconfigured by the OpenVPN gateway.

Large corporations, or companies with stricter internet rules still often set this.

My VPNtracker setting:

The same is also valid for IPsec. It all comes down to routing…

My 2 cents
Andy

@Andy_Wismer Thanks for the explanation.
This behavior fits perfectly to my use case. I can use my local PiHole without having to send the payload through the keyhole of my DSL-Upstream. Perfect! Just what I want.
It is inexplicable to me, however, why I have a download rate of 268 kB/s as shown in the screenshot, but without VPN 6,7 MB/sec.

@capote

Hi Marko

VPN takes some overhead, some CPU cycles for encryption.

OpenVPN seems - at least on NethServer - a bit “flakey” (Better word in German: Schwankhaft)…

My 2 cents
Andy

1 Like