VPN Throughput Calculator
Calculate effective VPN bandwidth with encryption overhead by protocol. Compare IPsec, WireGuard, and OpenVPN performance.
About this calculator
This calculator estimates real-world VPN throughput by combining two independent bottlenecks: how much of the underlying link's capacity survives encryption overhead, and how much the VPN gateway's CPU or hardware crypto engine can actually process. Effective VPN Throughput is the smaller of the two -- Link-Limited Throughput (Link Bandwidth reduced by the selected VPN Protocol's per-packet overhead relative to Interface MTU) and CPU-Limited Throughput (Firewall VPN Rating scaled by a protocol-specific processing-cost factor, since not every cipher suite costs the same CPU cycles per encrypted byte). Encryption Overhead and Effective MTU come from each protocol's fixed per-packet header/authentication cost -- IPsec AES-256-GCM's ESP header, IV, and authentication tag add more bytes than WireGuard's leaner header, so switching VPN Protocol changes both figures even with every other input unchanged.
The OpenVPN and SSL/TLS VPN overhead figures used here are representative planning estimates for common CBC+HMAC-style configurations, not a single universal standard -- modern AEAD-based OpenVPN setups can run leaner than the figure shown here, so treat those two protocols' numbers as illustrative rather than exact for your specific deployment. Per-Tunnel Bandwidth simply divides Effective VPN Throughput evenly across Concurrent VPN Tunnels; it does not model uneven traffic distribution between tunnels or per-tunnel rate limiting a real gateway might apply. Throughput Bottleneck names whichever side is actually constraining the result -- Link when the underlying connection runs out of bandwidth first, CPU when the gateway's crypto processing capacity runs out first -- which is worth watching whenever you change Firewall VPN Rating or VPN Protocol, since either can flip which side is the real limit.
Inputs
Results
Effective VPN Throughput
951.3 Mbps
Per-Tunnel Bandwidth
19.03 Mbps
How to Use This Calculator
- Enter Link Bandwidth, VPN Protocol, and Interface MTU.
- Set Concurrent VPN Tunnels and Firewall VPN Rating.
- Review Effective VPN Throughput (Mbps) and Per-Tunnel Bandwidth (Mbps).
- Use Link-Limited Throughput (Mbps) and CPU-Limited Throughput (Mbps) to inform your decision.
- Use the chart to visualize the results and explore different scenarios by adjusting inputs.
How the result changes with Link Bandwidth
| Link Bandwidth | Effective VPN Throughput | Per-Tunnel Bandwidth |
|---|---|---|
| 500 | 475.7 Mbps | 9.51 Mbps |
| 750 | 713.5 Mbps | 14.27 Mbps |
| 1,500 | 1,400 Mbps | 28 Mbps |
| 2,500 | 1,400 Mbps | 28 Mbps |
What each input means
- Link Bandwidth
- Underlying link bandwidth in Mbps
- VPN Protocol
- Encryption protocol and cipher suite terminating the tunnel.
- Interface MTU
- Maximum transmission unit of the underlying interface
- Concurrent VPN Tunnels
- Number of concurrent VPN tunnels/connections
- Firewall VPN Rating
- Firewall/VPN gateway rated VPN throughput from spec sheet
How this is calculated
Formula
Effective BW = min(Link × Payload/MTU, Firewall × CPU Factor)Worked example, using the default values
- Identify Input Parameters5 parametersLink Bandwidth = 1000, VPN Protocol = 1, Interface MTU = 1500, Concurrent VPN Tunnels = 50, Firewall VPN Rating = 2000 = 5 input(s) provided
- Calculate Effective VPN ThroughputEffective VPN Throughput951.3 = 951.3
- Calculate Per-Tunnel BandwidthPer-Tunnel Bandwidth19.03 = 19.03
- Calculate Link-Limited ThroughputLink-Limited Throughput951.3 = 951.3
- Calculate CPU-Limited ThroughputCPU-Limited Throughput1400 = 1400
Engine last updated . Checked against 1 independently-derived test — how we verify calculators. Built by Paul Gunder, a software engineer, not a licensed financial, medical, or legal professional.
Frequently Asked Questions
Why doesn't raising Concurrent VPN Tunnels change Effective VPN Throughput?
Effective VPN Throughput is the aggregate ceiling set by the link and the firewall's CPU, both of which are fixed regardless of how many tunnels share that capacity. Concurrent VPN Tunnels only changes how that same fixed total gets divided -- Per-Tunnel Bandwidth falls as you add more tunnels, but the aggregate Effective VPN Throughput itself stays the same because this calculator assumes tunnels share one pool rather than each getting an independent allocation.
What determines whether Throughput Bottleneck shows CPU or Link?
This calculator computes Link-Limited Throughput from Link Bandwidth and the VPN Protocol's packet overhead, and CPU-Limited Throughput from Firewall VPN Rating and that protocol's processing-cost factor, then reports whichever is smaller as the actual bottleneck. A slower link than the firewall can handle shows "Link"; an underpowered or under-rated firewall relative to the link shows "CPU" -- changing either Link Bandwidth or Firewall VPN Rating can flip which one is binding.
Why does switching VPN Protocol change Effective MTU even if Interface MTU stays the same?
Effective MTU is Interface MTU minus that protocol's per-packet overhead -- the bytes consumed by encryption headers, initialization vectors, and authentication tags before any of your actual data fits in the packet. IPsec AES-256-GCM's overhead (73 bytes) is larger than WireGuard's (60 bytes) in this calculator's figures, so the same 1500-byte Interface MTU leaves less room for payload under IPsec than under WireGuard.
Which input has the biggest effect on Effective VPN Throughput?
At the calculator's default values, Link Bandwidth moves Effective VPN Throughput by roughly 50% more than Firewall VPN Rating does, with Interface MTU's effect noticeably smaller than either. That ordering isn't a full-range guarantee, though -- because Effective VPN Throughput is the smaller of a link-side and a CPU-side ceiling, whichever side is currently binding is the one that matters, and at the high end of both ranges (fast link, fast firewall) Link Bandwidth and Firewall VPN Rating can move the result by nearly identical amounts. Once one side saturates the other, further increases to the saturated side stop moving Effective VPN Throughput at all.
Does a larger Interface MTU always help throughput?
Yes, within the model here -- a larger MTU spreads each protocol's fixed per-packet overhead over more payload bytes, so Effective MTU and the payload share of each packet both rise as Interface MTU rises. The effect flattens at very large MTUs (overhead becomes a tiny fraction of a huge packet either way), and this calculator does not check whether your actual network path supports the MTU you enter without fragmentation.
Related Calculators
The questions that sit next to this one — chosen by subject, including calculators filed under a different category.
Bandwidth Capacity Planner
Calculate required network bandwidth from user count, application profiles, concurrency, and protocol overhead.
Network DesignNetwork Latency Calculator
Calculate round-trip time from hops, distance, processing delays, and queuing. Includes VoIP quality assessment and TCP throughput estimate.
Network DesignNetwork PoE Budget Calculator
Calculate Power over Ethernet budget from device count and power draw. Verify switch PoE capacity for phones, APs, cameras, and more.
More in Technology & Computing.