Windows RRAS NAT Vastly Slows Down Native (Non-VPN) TCP Connections of Server

Server Fault Asked on January 3, 2022

So I have a Windows Server 2019 (Server A) set up with the RRAS (Routing and Remote Access) role. It is configured with the built-in NAT in such a way that VPN clients have access to the internet via the server’s public interface.

For clients this works flawlessly, but native connections (e.g. TCP) from the server itself (Server A, which runs the RRAS role) become laughably slow. (Connections to Server A work as fast as expected) When testing via PowerShell’s Test-NetConnection I get successful TCP connections to a remote TCP server (Server B) (completely unrelated to the VPN/Server A, EDIT: but with an IP that has the same network prefix) that take up to 15 seconds (sic!) to complete.
Pings from Server A to the exact same Server B are in the ballpark of single-digit milliseconds and work without any delay, irrespective of RRAS/NAT settings.

The issue only comes up if RRAS is enabled with NAT AND the RRAS network interface is enabled (i.e. after startup of the server or startup of the RRAS service there was at least one client connected). Before this state or if NAT is disabled for RRAS, connections establish almost instantly.

I first manually deleted all RRAS relevant routes in the routing table – to no avail. Then I inspected the packets with WireShark. Turns out the TCP packet exchange and packet reception are just as fast as if RRAS NAT was disabled. Seems like the packets are simply not properly forwarded to the program executing the request.

What’s boggling my mind is that the connection eventually does succeed, but is simply excrutiatingly slow. What could be the culprit here? Do I have to resort to a separate RRAS VPN Server?

Add your own answers!

Related Questions

RAID status monitoring HPE Smart Array E208i-p SR Gen10

2  Asked on November 7, 2021 by halfgaar


What does SATAu mean on Dells driver carriers?

1  Asked on November 7, 2021 by miho


squid : Block destination Subnet or IP addresses

1  Asked on November 7, 2021 by bhalu


Giving a guest user in Azure access to a VM

1  Asked on November 7, 2021 by kobus-myburgh


How to Disable Nginx’s module Nchan

1  Asked on November 4, 2021


ping command is not printing result to the console

1  Asked on November 4, 2021 by user583819


How to find out who created a Azure Service Bus queue?

0  Asked on November 4, 2021 by dijkgraaf


Ansible – copying and editing a remote file at the same time?

1  Asked on November 4, 2021 by kevin-keane


Problems with WEBDAV on lighttpd

0  Asked on November 4, 2021 by user3670606


Ask a Question

Get help from others!

© 2023 All rights reserved. Sites we Love: PCI Database, MenuIva, UKBizDB, Menu Kuliner, Sharing RPP, SolveDir