DrayTek UK Users' Community Forum
Help, Advice and Solutions from DrayTek Users
Draytek 3910 4.4.6.3 IPsec strange behaviour with routing between sites
- tony.lacey
- Topic Author
- Offline
- New Member
-
Less
More
- Posts: 3
- Thank yous received: 0
29 Sep 2026 13:53 #107015
by tony.lacey
Draytek 3910 4.4.6.3 IPsec strange behaviour with routing between sites was created by tony.lacey
Just putting this out there in case anyone else comes across the problem - no you're not going mad.
Situation: IPsec site-to-site VPN between two Draytek routers, one of which is a 3910 updated to 4.4.6.3. Traffic between both sites is perfect.
However, users remotely logging in using L2TP/IPsec to the 3910 get horrible performance on traffic routed from the 3910 to the satellite site. SMB, RDP, and ICMP are all awful. The most clear indicator is ANY IP address remote from the primary (3910) site has 50% ICMP drop-out (every second ping packet), for any packet size, except when you exceed the MTU and suddenly 100% success rate. This doesn't affect other VPN protocols (connect to the 3910 via a WireGuard connection - no problem, for a satellite site connected via WireGuard, no packet loss to that site, even when dialling in with L2TP/IPsec). I've replicated this test on a completely separate 3910.
Now I just need to work out how to report this to Draytek!
Situation: IPsec site-to-site VPN between two Draytek routers, one of which is a 3910 updated to 4.4.6.3. Traffic between both sites is perfect.
However, users remotely logging in using L2TP/IPsec to the 3910 get horrible performance on traffic routed from the 3910 to the satellite site. SMB, RDP, and ICMP are all awful. The most clear indicator is ANY IP address remote from the primary (3910) site has 50% ICMP drop-out (every second ping packet), for any packet size, except when you exceed the MTU and suddenly 100% success rate. This doesn't affect other VPN protocols (connect to the 3910 via a WireGuard connection - no problem, for a satellite site connected via WireGuard, no packet loss to that site, even when dialling in with L2TP/IPsec). I've replicated this test on a completely separate 3910.
Now I just need to work out how to report this to Draytek!
Please Log in or Create an account to join the conversation.
Moderators: Admin3, Christopher