KB5025305 causes speed issues on L2TP/IPsec VPN

Been seeing issues with MS Update KB5025305 causing speed issues with Client VPN. No problems connecting to the VPN, just once you get in the speeds are extremely slow and RDP basically just times out. A quick search of the web confirms that KB5025305 causes speed issues on L2TP/IPsec VPN. Does anyone know of a fix for the issue instead of uninstalling the Update?

Enabling “Routing and Remote Access service” fixed the problem for me.

I’m having users with the exact same problem, I’ve got 5-15 users out of 43 with that problem and not all have that update I just verified, everything from 4th-11th gen I tell, laptops and desktops, windows 11 and 10, any connect and windows built in,
We even tried rolling back to 17.10.2 firmware on our mx and it didn’t help, we’re on 17.10.5 now.

I’ve got an escalated ticket in the meraki support I’m awaiting a call back on

Same sh*t for my customers.

An interesting thing is that when using L2TP VPN via wifi the speed is up to 1Mbps, when switching to wired the speed is up to 100Mbps.

Internet connection was dropping out when connecting to L2TP/IPsec VPN. Uninstalled KB5025305 update and now the VPN and internet connection are working fine.

Same issue reported here: https://community.meraki.com/t5/Security-SD-WAN/Windows-11-Very-Slow-VPN-Connection/td-p/125179

Hi, found this only affects l2tp over wifi. Via ethernet is OK.

Temp work around, install glasswire or Wireshark (run a packet capture on the WiFi card once). If you uninstall, it breaks again.

Very interesting. I have also confirmed the wireshark packet capture fixes the issue. However I don’t know if this update is affecting windows 11 enterprise. Forsure windows 11 pro.

I’m having this same issue with 2 devices at a client who has multiple sites. 2 devices connecting to 2 different site VPNs. Users are 150+ miles apart from one another within the state and have different ISP’s. Both experiencing killer download speeds, 0.75~0.87mbps with ~5mbps upload while connected to VPN. Connecting to shares trying to open docs or save to the share completely locks up the pc, file explorer shows not responding then eventually crashes. There’s severe latency with my remote connection as well. When not on the VPN everything is fine. Quick and snappy as it should. One device gets 105mbps down and the other over 500mbps down. Both are on WIFI…I had the idea of connecting ethernet but neither had a cable. Also unsure if they have capabilities to do so with their home setup (modem, router, etc.). I am going to assert them to try this before attempting the Wireshark method if they’re able. It is just not idea for these users and will be a last resort effort.

Thankful for coming across this post. Both devices have recently been updated and now this surfaced. Both are on 11, unsure of build. I will review the updates and try uninstalling as well if no ethernet cable is immediately available or if their device doesn’t have an ethernet port. I think both are Dell but not sure of their models. I’ll review system info in the monitoring software. Really thankful as everyone I have communicated with has never seen it but has said its got to be a device issue and not VPN as others are connected and no issue. It’s had me stumped as all hell and both users went into office today so could not troubleshoot further. I have read through here, the Meraki forum post and the reddit thread that is linked in that forum post and I’m ready to go in Monday and attack it haha.

Confirmed that fully updating windows 11 and running wireshark increased VPN speeds from .5/1 up/down to 60/40 for our client having issues. Thanks guys!

Hey guys - not too familiar with wire shark. Do I just open up the app and click “start capturing packets” on the WiFi card? It seems to run for a long time. Will it eventually stop and then vpn speeds improve?

Thx

Hey - anyone have a permanent fix for this issue? I recently updated the firewall firmware and installed the latest MS patch, still having very slow vpn speeds for some win11 users

A percentage of our customer base that has this issue are using eero wifi-routers. eero solution was simply to setup a local guest wi-fi. Not a good solution, but improved speed for most users. Anyone else seen this issue with other brands of home user routers?

just incase anyone is wondering, issue seems to be on 11 Pro and also Enterprise, ive changed to an enterprise license and problem still there, also the problem has come back even after the wireshark temp fix, uninstalled it and rebooted wireshark, donethe same again but no change in VPN just stay slow now, anyone had this?

Do you have to be connected to your VPN when running a packet capture via Wireshark? I’ve never used Wireshark, but I have been having this issue with our office VPN for about a month now. I’ve downloaded Wireshark and am trying to run it while VPN connected, but everything is so freaking slow, it doesn’t seem to be doing anything.

This is still ruining VPN speeds for a half dozen users. For most, I was able to roll back the updates to build 22621.1555 where the VPN works.

For a few users, update KB5026372 will not uninstall via normal GUI, CMD, PowerShell, or even the Windows Update Utility, so they have to use the Wireshark work around which is just terrible for an end user to have to do.

Anyone have a new fix? It’s been over a month since Microsoft broke their own VPN…

there’s no way it’s that simple

this worked for me too! thank you so much! i’ve tried all of the above (without rolling back 4 builds)… the closest thing that came close was keeping WireShark packet sniffing but this works much better. many happy L2TP users again!

Also worked for me… Thank You!

As u/philm98 said, there’s no way it’s that simple…

But this definitely fixed my problem on all Windows devices on my network, so thanks!