This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Endpoint slow down internet speed

Hello,

We got a dedicated optical fiber 1gb Down/up .

With the endpoint installed, the speed download seems to be block around around 150 to 300 mb/s. Upload is correct.

IF i uninstall it, then the speed go back to normal with around 900 mb/s. Tests are made through NPERF. 

I tried a to play with settings on sophos central but none of them seems to make it work normally.

Does someone experiencing this issue or does know how to fix it ?


Note: Please see the following Blog Post for the latest update regarding this issue



This thread was automatically locked due to age.
  • Is the process SophosNetFilter.exe running or not with that change?

    Is scan downloads in progress still enabled?

    Is web control on or off?

    If it’s just block access to malicious websites that needs to be disabled and downloads in progress can remain on the SophosNetFilter.exe will still be running. This is a bit odd that you think things have improved unless the slowness for you came from either the lookups for the websites or the overheads of the decryption.

  • I just called Sophos tech support at 2:09PM EST and was told "Core Agent 2022.4.0.4 is schedule to be released 01/17/23 as a general release".

  • I just called Sophos tech support at 4:12PM EST and was told "Core Agent 2022.4.0.4 is still scheduled to be released 01/17/23.

  • Sophos tech updated our central with 2022.4.0.4. As soon as our computers were updated, the problem dissapeared.

  • We already have 2022.4.0.4 but the issue is still the same -  1 GBs WAN but if INTERNET ond / or WEbfiltering is on it slows dows to ~100MBit -  700 Clients - with a lot of TEAMS fun -  bad Quality 

  • We are in the supposedly final version of Core Agent 2022.04.04 and the problem still continues, I have opened 2 cases and it still has not been solved.
    Case Number: 06075953
    Case Number: 06011169

  • I work for an MSP and Sophos Endpoint continues to be a massive headache for us with this type of nonsense. Over 2000 endpoints.  We just onboarded a new client and they immediately felt something was off after fully deploying Sophos Endpoint Intercept X Advanced.  A client with a 1GB internet connection.  These pictures speak for themselves and we even did this with a direct connection to the ISP cable modem, bypassing all internal hardware equipment.  Client is on latest version 2022.4.0.4.

    Something needs to be done about this and I don't want to hear BS about browsers or command line testing.  I cannot contact a client and tell them, well look, it checks out fine via some command line test.  There is a problem with this feature of the product and fully disabling multiple features, including Network Threat Protection cannot be an option.  Fix this before we end up in a discussion about leaving Sophos for good.






  • I was having these problems even with version 2022.4.0.4, I even opened a support case, in my case it only improved by disabling Protect network traffic, but the idea is not to be disabling components, but the strange thing is that after that I went back to Activate it and the problem no longer occurred, since yesterday I no longer presented degradation, I really don't know what is happening with Sophos, but this is becoming more and more problematic.

  • What is modernweb.offloading.enabled set to under:
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sophos Endpoint Defense\EndpointFlags

    Thanks.