Telnet over WAN latency troubleshooting



We've got a couple of sites that are losing their longstanding 32K
leased line connections using MUXserver 90s and DECmux 308/316s. That
service has been working for years, but the area telco is skyrocketing
the price to the point that, when tied to the inability to support the
aging hardware, its just not reasonable to keep it.

The customer has ADSL circuits (256K up, 1.5M down) at each location,
with the same ISP, and all in the same region. Traceroutes between the
three sites indicate traffic does not leave the ISP's infrastructure.

Speed tests indicate they are getting around 210K up and 1200K
downaround noontime to various speed test sites; we have not been able
to test other times because two of the three locations don't have a
computer at them, just a DECserver 90M+ (DNAS V3.2) and VT terminals.
One site to site test from each remote to the central Alpha was
performed that showed about the same throughput, but we can't repeat
that test (the peecee used was the installer's notebook). The central
site has the host system, a DS10 running VMS V7.3-1 and TCPIP V5.3 ECO
4, all patched up on class 1 and 2 patches.

The two remote locations have no other internet usage. The central
location has moderate PC usage, but the problem occurs even when all
the central PC users have shut down.

The sites are tied together using Sonicwall TZ170 firewalls, standard
firmware, and firewall-to-firewall VPN tunnels. We use these firewalls
at numerous locations and have not had problems like this in the past.

We're getting terrible latency on interactive telnet sessions. There
are no locateable problems on any of the LANs (per the various system
and device counters). Firewall and tunnel MTUs are set at 1404 bytes
due to underlying PPPoE service provided by the telco, and we've tried
using tunnel bandwidth reservation and service based rules (for telnet)
bandwidth reservation without any impact; we've also tried the old
culprit SET PROTO TCP/NODELAY with no perceived change in behavior
(didn't expect any with that one, though; it was just worth a shot).

Pinging from the Alpha to the remote decservers (through the tunnel)
with 1200 byte packets I see zero packet loss except for peak time
usage (~1PM to 6PM) where it rises to up to 5% (rare, 3% every day).
Pinging to the remote DSL router LAN port (the gateway address for the
firewall) I see about 1% less packet loss. Ping times are fine either
way; about 120 - 140ms (small pings get through in 50-60ms).

I still think its the ISP's problem, given the measurable packet loss
in the afternoons, but we've already bounced off their tech support 4
times (they refer it up to Bellsouth, where it goes to places unknown
and never returns).

I need to find out if there's any way to get telnet to work more
efficiently over the link we have now. I don't see anything in the
DNAS documentation that appears useful but I'm still digging. Are
their any parameters in DNAS or TCPIP services for optimizing
interactive (telnet) service over what is apparently a high (or at
least sporadically high) latency link?

Thanks for any info.

Rich
CCS

.



Relevant Pages

  • Re: VPN question
    ... You have such an odd design and I have ... Not all firewalls run NAT, and firewalls inside the> internal network is necessary to separate traffic in different security> zones and inspect traffic between zones. ... >> You have to run one Tunnel inside the other Tunnel to even get across> a B2B ...
    (microsoft.public.windows.server.networking)
  • Re: VPN question
    ... > network and the RRAS/ISA server in the perimeter network. ... > is forwarded to the security zone (subnet), through a new tunnel, to get ... You have to run one Tunnel inside the other Tunnel to even get across a B2B ... Your intent to do this with firewalls is just simply wrong. ...
    (microsoft.public.windows.server.networking)
  • Re: VMS cluster behind a *NIX firewall
    ... There is no access to raw Solaris for outsiders to attack (unless ... you are talking about homegrown firewalls rather than commercial offerings). ... I have had telnet turned off on every server box of any kind ... the VMS community. ...
    (comp.os.vms)
  • Re: SSH Connecting through Firewall
    ... >Reminds me of a presentation I saw, showing how with cooperating hosts ... >inside and outside of a firewall, it's possible not just to tunnel out, ... many firewalls (including some "stateful" ones, eg the last time I looked ... the default options for Firewall-1 allow ICMP echo and echo-request). ...
    (comp.security.ssh)
  • Re: VPN question
    ... By tunneling traffic inside the internal network you do not have to open ... Not all firewalls run NAT, ... > You have to run one Tunnel inside the other Tunnel to even get across ... >> I do know that security in the LAN is one thing, ...
    (microsoft.public.windows.server.networking)