Hello,

I am hoping someone can point me i the right direction here. I have a weird home networking issue which I just do not understand at all. My set-up is a Ubiquiti USG-Pro 4, connected to a managed 8 port ubiquiti switch and then a generic 24 port unmanaged switch with various kit plugged into it including a qnap NAS running container services such a PiHole, Deluge, Plex, Nextcloud etc.

I have 3 access points (PoE) connected to the 8 port switch to run my wireless network and I also run some wired and wireless cameras with Unifi Protect

Everything runs fine EXECPT…

Whenever any device (laptop \ mobile \ container running within the NAS \ whatever) connects to my VPN provider (ProtonVPN) and starts to download any sizeable data via that VPN link, my network latency on the USG goes from an average of 16 ms up to a network breaking 500+ ms.

I have tried…

  • Turning off all IPS \ IDS \ traffic monitoring on the USG
  • Completely replacing my generic unmanaged switch for another brand
  • Downloading torrent files from P2P networks
  • Downloading large files directly from the internet
  • Removing PiHole as my DNS server (switching directly to 1.1.1.1)
  • Using OpenVPN and Wireguard protocols

I have experimented downloading from the QNAP NAS, from a wireless connected laptop, from a mobile phone, from a wired computer with and without the VPN connected.

Without the VPN - all is good, speed is good (I have a 500GB down ISP connection) and latency is good (well below 18 ms at all times)

With the VPN - all starts fine but within 30 seconds or so latency is up at above 500ms and the rest of the network slows to a crawl.

I am staring to think that this may be an issue with the processing capabilities of the USG? or am I missing something really obvious here. Any advice appreciated.

  • bigredgiraffe@lemmy.world
    link
    fedilink
    English
    arrow-up
    2
    ·
    11 months ago

    You may be right about the processing power, that device was underpowered when it was new. Do you have the VPN terminating on the USG or on the end device?

    Also, do you have smart queuing disabled on the WAN interface? That causes all kinds of issues on higher bandwidth connections.

    • Urbanmoth@lemmy.worldOP
      link
      fedilink
      English
      arrow-up
      1
      ·
      edit-2
      11 months ago

      I have tried smart queues on and off - no difference. The VPN is terminated on the client at my end - this is why I am finding this so confusing. Someone else has suggested it may be my ISP throtttling VPN traffic which actually would make more sense than the USG processing power to my mind. :(

      {edit} mind you - that would not impact local network traffic so that cannot be it !

      • bigredgiraffe@lemmy.world
        link
        fedilink
        English
        arrow-up
        1
        ·
        11 months ago

        That’s interesting, this definitely is an odd problem for sure haha. Another wild idea, do you have jumbo frames enabled anywhere on your network?

        As for the ISP, it might be, have you tried multiple VPN providers to see if the problem follows between them?

        • Urbanmoth@lemmy.worldOP
          link
          fedilink
          English
          arrow-up
          1
          ·
          11 months ago

          Jumbo frames not (and never has been) enabled. Yes, I think my next investigations is going to be the VPN itself. If I ever track this down I’ll post back just for closure :) Driving me nuts!