It’s the weekend, so I’m able to do more testing now. I feel like I’m closing in on the issue with some more tests.
To recap - this is a Balance One, with 2 WANs, one of which is a Spectrum cable modem which is provisioned for 480mbps download speeds. With latest firmware, I’m not able to get advertised speeds. Unlike other users, I have not found a specific setting with 8.1 that is causing the speed loss…
This morning I ran tests using old firmware versions, and the results are illuminating:
Speed CPU Firmware Comments
--------------------------------------------------------------------------
480mbps 7.1.2 full speed
480mbps 97% 8.0.0 full speed - CPU is maxxed out
240mbps 70% 8.0.1 about half speed - CPU is not maxxed out
240mbps 8.0.2 about half speed
240mbps 8.1.0 RC3 about half speed
From this testing, the problem is not new, but rather shows up in the jump between firmware 8.0.0 and 8.0.1.
Looking at the 8.0.1 release notes ( https://download.peplink.com/resources/firmware-8.0.1-release-notes.pdf ) and thinking about what features I’m using or that could conceivably cause a system-wide performance decline, I found these:
18627 [AP Controller] Added Fast Roaming 802.11k, 802.11r, 802.11v support
Comment: I am using fast roaming, although since all my tests are over Ethernet, I don’t think this is likely to be causing an Ethernet slowdown.
20896 [Firewall] Local Service Inbound Firewall support
Comment: I am using local service firewall rules. I’ve tested with them disabled and seen no changes, but this still could be relevant.
20822 [QoS] Added Youtube and Netflix applications.
Comment: I’m not using any QoS settings, but user oakhurstmgmt has reported these are causing the problem for them.
21161 [SNMP] SNMPv3 Authentication and Privacy passphrase supporting special characters
Comment: I am using SNMP, but I’m not using SNMPv3, but perhaps some code changes in SNMP are causing trouble?
20998 [System] Fixed for TCP SACK CVE-2019-11477 CVE-2019-11478 CVE-2019-11479
Comment: any chance these fixes broke somethign with TCP ACKs? Suppose every other ACK was getting lost or delayed, that could explain a 50% download speed loss.
Next tests: I’ll go to 8.1 RC4 and see if I can factory reset and add my settings back one-by-one as oakhurstmgmt has done above.
Edit : Found the bug. See Outbound Policy Rule using Domain Name cuts bandwidth in half