fosrl / fosrl/pangolin

Connection relayed even though client shows it as local

Open
#3,634 6 comments 0 reactions 0 assignees View on GitHub
Dominant language
TypeScript
Stars
22.8k
Forks
783
Avg merge
1d 7h
Merged PRs (30d)
52

Description

### Describe the Bug

My Windows PC and my Unraid Server where Newt lives are on the same LAN and the Windows Client also correctly reports the connection as local. When I connect to a resource like OpenSpeedTest however, I get speeds of only around 100 Mb/s Up and Down, even though the Server and my PC are both connected with 2.5Gb Ethernet.
In Packet Capture in pfSense I can see my PC sending packets to the IP of my VPS and the VPS sending packets to Newt, but no traffic between my PC and Newt directly during a speed test. The other services on the same server I've tested (Nextcloud, Erugo and Immich) also exhibit upload speeds that imo cannot be the result of a (properly working) local connection. It doesn't matter if I configure them as private http or public resources. Connecting to their respective IP:Port via http, the transfer speeds from the same PC are as expected (~2400Mb/s Up and Down).
I read through the official forum about router quirks and made sure to enable Static Port Mapping for my NAT.

### Environment

- OS Type & Version: Windows 11 Pro 25H2
- Pangolin Version: 1.21.1
- Edition (Community or Enterprise): Enterprise
- Gerbil Version: 1.4.3
- Traefik Version: 3.7.10
- Newt Version: 1.16.0
- Client Version: Windows Client 0.14.0

### To Reproduce

1. Connect to Pangolin
2. Make sure connection shows as Local
3. Connect to any resource
4. observe non-local transfer speeds

### Expected Behavior

The speeds should be about the same as connecting directly via http when the Pangolin client shows the connection as not being relayed.

Contributor guide

Open the contributing guide

Research direction

Reproduce the issue with the Windows Client, Pangolin, Newt, Gerbil, and the listed versions, then compare pfSense packet captures for a connection reported as local. Done means local resource traffic goes directly between the Windows PC and Newt and reaches speeds comparable to direct HTTP access rather than being relayed through the VPS.

Written by the indexing model from the issue text.

Assessment

Tech stack
typescript
Domain
networking
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Active
Clarity
Mostly clear
Newbie friendliness
45/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.