the router asus RT-N66U running dd-wrt firware
With standard firmware the RT-N66U can't terminate IPSec and L2TP tunnels and only supports pass through for these VPNs. It can terminate PPTP tunnels as well as pass through.
PPTP is a lightweight low security encryption that is less processor intensive than IPSec and L2TP. This rather tells us that the router doesn't have any dedicated hardware encryption processing and isn't very suitable for heavy duty encryption/throughput combinations.
I wouldn't be at all surprised if this is the bottleneck.
To put things in perspective, the £400 Watchguard XTM 25, which is a dedicated firewall without wireless, only has a VPN throughput of 40Mbps. The Draytek 2930 has a similar VPN throughput. For a 100Mbps VPN throughput on a Watchguard product you'll need to spend £815 for the XTM 33.
I think you're doing remarkably well to get 25Mbps on the RT-N66U - I'm impressed!
Edited by caffn8me (Mon 22-Sep-14 19:08:41)