This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

UTM 9 Software appliance slow download/upload speeds

Hey Guys, just wanted to see if you could point me into the right direction. I have a software appliance running on a Hyper-V server windows 2010 with 15G or RAM and 512GB of disk. Nothing else runs on it. The machine is strictly dedicated to UTM9.

When I fist build it, the speeds were just fine 200Mbps/200Mbps. No major changes, beside some NAT rules for port forwarding that were made. I've also disabled them later during the testing with the same results.

Recently the speeds dropped to 10/20Mbps. I've connected my laptop directly to ISP router and was able to regain 200/200 speeds.

I've read a few post in Sophos communities, but still no luck. I've disabled all types of network protections, Anti-DDoS, web filtering, anti-portscan...etc but nothing has changed.

The hardware performance are steady at CPU=8%, RAM=10-15%, Log Disk=1%, and Data Disk=7%. All the hardware resources (windows machines) all dedicated to UTM.

I checked the Interface settings, under advanced and all set to 1000Mbps respectfully.

The windows Machines NIC's all set to 1Gb under hardware performance.

Everyone's help is greatly appreciated. 



This thread was automatically locked due to age.
Parents
  • Hey LS - welcome to the UTM Community!

    The Realtek NICs are a known no-no with the UTM (see #7 in Rulz), but I would have expected Hyper-V to prevent that.

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
  • Thanks Bob; Would you of a recommended vendor or a practice for the NIC settings?


    Appreciated.

  • In addition to the info in #7, check out the last two pages of the "Unofficial HCL" thread pinned to the top of the Hardware forum.

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
  • Updating to the latest Zotac firmware didn't resolve.

    Bob - if I save my configuration, would I be able to restore it to another machine later?

    IE, if I replace the Zotac with a different appliance with Intel NICs, would that configuration work on it?  I'm not sure if the export is just app configuration settings, or it stores anything specific to the hardware it is installed on...

    Thanks.

  • Figured it out, as posted on a Zotac specific thread as well (https://community.sophos.com/products/unified-threat-management/f/hardware-installation-up2date-licensing/108219/anyone-using-a-zotac-box-ci327/390330#390330)

    My throughput issue is not related to Sophos or a recent firmware update. Good for Sophos, bad for Zotac and me unfortunately. 

    So my recommendation is to test your hardware outside of the Sophos VM, and see if you can get full speed there.  If not, your Realtek NIC could be failing.  That is what I've now proven on my Zotac, a hardware failure.  I could not get full speed in three different scenarios on the Zotac (see thread).  

    I'm now in the market for a new hardware appliance. 
    And per my question before, if I can just restore from the backup I have downloaded, I will do that. If not, I'll be comparing UTMs again.

  • You can restore a configuration backup from non-Sophos hardware to any other non-Sophos hardware.  With Sophos hardware, if moving from an SG 210 to an SG 230, for example, a license for a 230 must be applied after the restore.

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
  • interesting; I'll have to test my NIC. it's possible it might have gone bad, since I did not buy it new and rather used an old one from my other PC. Thanks.

     

    I actually been talking to Sophos support and they have taken an interest in this case. I tried a few suggested alteration without success. They are looking to get into my system and collect data. 

    I'll keep everyone posted once I complete this task. 

  • It does starting to look like a possible a bad NIC hardware. I can't even change the speed on interfaces. No option is available. 

    Trying to figure out how to attempt this change via CLI.

    Going to the store tomorrow to get a new hardware.....and NOT a Realteck.

     

  • When changing hardware you should of course also select a system with at least as many NIC's as your previous system has. Then again, the order of the NIC's might do something strange. I build one machine once which had 2 NIC's of itself and put a 4 NIC card into it to have a total of 6.

    1 of the Onboard NIC's was eth0, eth 1-4 were on the additional board and eth5 was again on the mainboard.....


    Managing several Sophos firewalls both at work and at some home locations, dedicated to continuously improve IT-security and feeling well helping others with their IT-security challenges.

  • Well, looks like it was a hardware. I pulled my Realtec NIC out and replaced it with HiRo (I got a cheap one to make sure this was an issue) and just so happen, it resolved the issue. 

    Thanks

  • I've recently learned something and wanted to provide an update for anyone using ATT Fiber.

    The Pace 5268AC gateway firmware upgrade to 11x has an issue with the DMZ+ mode which impacts throughput to about 50/200 max.

    So...if you happen to have ATT Fiber, the Pace gateway, and your UTM in its' DMZ...

     

    https://forums.att.com/t5/AT-T-Fiber-Equipment/PACE-11-1-0-531418-DMZ-Issue/td-p/5700776

Reply Children
No Data