this post was submitted on 07 Oct 2025
20 points (100.0% liked)

Selfhosted

52107 readers
854 users here now

A place to share alternatives to popular online services that can be self-hosted without giving up privacy or locking you into a service you don't control.

Rules:

  1. Be civil: we're here to support and learn from one another. Insults won't be tolerated. Flame wars are frowned upon.

  2. No spam posting.

  3. Posts have to be centered around self-hosting. There are other communities for discussing hardware or home computing. If it's not obvious why your post topic revolves around selfhosting, please include details to make it clear.

  4. Don't duplicate the full text of your blog or github here. Just post the link for folks to click.

  5. Submission headline should match the article title (don’t cherry-pick information from the title to fit your agenda).

  6. No trolling.

Resources:

Any issues on the community? Report it using the report flag.

Questions? DM the mods!

founded 2 years ago
MODERATORS
 

Hello I hope one of you can help point me in the right direction.

I have a VPS with a static IP and a wireguard tunnel from VPS to home network (no bridging in the router, just point-to-point with specific devices).

I found an abysmal connection speed with bandwidth on the order of 50-100 kbps tested via iperf. Connection between the same devices outside the wireguard tunnel is 10-20 mbps, which is 100-400 times slower, which I don't understand since wireguard usually has very little overhead.

I have tried different MTU settings on both VPS and devices on my home network (both cabled and via wi-fi) in the range from 1360 to 1460, and above speeds are the best I have reached with MTU 1420 and 1440. I have tried both with and without iptables rules setting the mss correspondingly.

The above speeds are acceptable for incremental backups and document synchronization, but completely unsuitable for media streaming.

Where would I start diagnosing the bottleneck?

Thanks in advance.

UPDATE 2025-10-09:
I have not figured the issue out yet, and I do not know where to go from here.
I found a single similar issue (asymmetric wireguard speeds) here: https://forum.openwrt.org/t/wireguard-client-upload-slowness/190772, but that was resolved by changing MTU.

It must be a VPS issue, since when testing from multiple clients on different networks and locations, the bandwidth from client to server does not vary.
I have tried MTU from 1280 to 1460. Current best settings, MTU = 1440 on client and server, and an iptables rule:
iptables -t mangle -A FORWARD -p tcp --tcp-flags SYN,RST SYN -j TCPMSS --clamp-mss-to-pmtu.

Via tcpdump I have confirmed that the two endpoints negotiates an mss of 1460 (outside wireguard), making an MTU of 1420 to 1440 appropriate for the wireguard tunnel.

UDP without wireguard can saturate network connection.
TCP without wireguard has about 50-60% slowdown compared to UDP.
Bandwidth from vps to client is decent inside wireguard tunnel.
Bandwidth from client to vps inside wireguard tunnel is still abysmal.

Current speeds UDP:

  • UDP, no wireguard: 16 mbps (client to vps) (at the time of testing, saturates client connection upload)
  • UDP, no wireguard: 270 mbps (vps to client) (at the time of testing, saturates client connection download)
  • UDP, wireguard: 80 kbps (client to vps)
  • UDP, wireguard: 106 mbps (vps to client) Current speeds TCP:
  • TCP, no wireguard: 8 mbps (client to vps)
  • TCP, no wireguard: 117 mbps (vps to client)
  • TCP, wireguard: 280 kbps (client to vps)
  • TCP, wireguard: 4 mbps (vps to client)
you are viewing a single comment's thread
view the rest of the comments
[–] stavefajl@feddit.dk 1 points 2 days ago (2 children)

I am currently running mtr from multiple devices:

  • in wireguard tunnel: single hop 10.1.1.1, loss% 0,1, avg ping 27.4 ms
  • outside wg between same devices:
    • ISP supplied modem/router 55% loss, avg ping 1.6 ms
    • multiple hops without loss, avg ping 16-20 ms
    • random intermediary 30 % loss, avg ping 20 ms
    • endpoint, 5% loss, avg ping 25 ms

It looks like across the board my ISP modem / router is dropping 50-80 % of packets, and that packet loss is ramping up from 4% to 80 percent after a few minutes of running mtr.
It also looks like my VPS endpoint climbs to 20% packet loss over time (5-15 minutes of testing).

Can I use this information to probe further into the devices I have access to (ISP modem and VPS)?

[–] Brkdncr@lemmy.world 1 points 2 days ago (1 children)

Some devices will drop icmp packets. Does iperf show the same amount of loss?

Can you try a different internet connection such as mobile hotspot just to see if you have similar results? That could help identify it as a vps issue.

[–] stavefajl@feddit.dk 1 points 2 days ago

I had to borrow a phone to set up a mobile hotspot.
It has the same speeds inside the wireguard tunnel as when I tested from my wired connection (250 kbps TCP, 170 kbps UDP).
The loss reported by iperf is dependent on the bandwidth that i test with. But as I increase bandwidth from the client the loss grows towards 100%.

I tried testing in reverse (sending from VPS to devices on different networks) with surprising results:

  • TCP, wireguard: 5-10 mbps
  • UDP, wireguard: 50 mbps
  • TCP, no wireguard: 45 mbps
  • UDP, no wireguard: 250 mbps (saturates download speed on client when compared to speedtest.net)