This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Sophos XG 105: hardware ISO performs betters than software ISO with home license on XG hardware? Is sophos limiting speeds when using home licenses on Sophos hardware?

Dear community,

I am testdriving a XG105 that I got from a friend who works at an IT company to test out the performance. I currently have a 200/200 fiber internet connection.

After installing the hardware ISO (HW-17.5.1_MR-1-347) and running the installation wizard, I got a speed result of 160Mbps with all protections enabled in the wizard.

However: after installing the software ISO (SW-17.1.4_MR-4-254) with a Home license and running the installation wizard with exactly the same protections enabled, I got a speed result of 30 Mbps.

How is this possible?

Has Sophos limited the speed of XG home installations on Sophos XG hardware?

(I remember that on an older UTM120 device there was NO speed difference between software and hardware installations of UTM and XG.)

 

[*-)]



This thread was automatically locked due to age.
Parents
  • Depends solely on the hardware. On a test server (2x Xeon, 32gb RAM, SAS drives) I got with Home license the throughtput is dead on 200/200 as the line is.

    Probably the Software ISO doesn't fully utilise the hardware on the XG and that's the reason there's a hardware ISO and a software ISO. If the hardware ISO works well, stick to it.

  • But I cannot use a home license on the hardware XG installation isnt it?

  • Whoops, sorry about that! I misread your topic!

    AFAIK the hardware ISO doesn't accept home keys, so you're stuck with the software ISO. 

    Are you sure you did the same setup as with the hardware one? I would assume a 20-30% loss ok with that, but 30mbit performance is way too low. I've got 17.5 on a asg 110/120 that performs better!

    Upgrade the Software XG to latest version and retest

  • Panagiotis Vakerlis said:

    Whoops, sorry about that! I misread your topic!

    AFAIK the hardware ISO doesn't accept home keys, so you're stuck with the software ISO. 

    Are you sure you did the same setup as with the hardware one? I would assume a 20-30% loss ok with that, but 30mbit performance is way too low. I've got 17.5 on a asg 110/120 that performs better!

    Upgrade the Software XG to latest version and retest

     

     

    Hi Panagiotis,

    I reinstalled the software version of XG 17.5.1 and did the installation wizard again.

    I compared the firewall rules with the earlier installed hardware version of XG 17.5.1 and I got the following results again:

    XG105

    • Installed with hardware version of XG 17.5.1: 160-190 Mbps download speed
    • Installed with software version of XG 17.5.1: 30-40 Mbps download speed

    So I really suspect that Sophos is downthrottling the network speeds of software XG installs on XG hardware.

    Or would this be also the case for ANY other software XG installation on NON-Sophos hardware?

  • Like I and  noted, there's no way the Software is downthrottling. I have a live example on my server which started with 40/4mbps upgraded to 60/20 and now 200/200. Throughtput is full on internet speed and gigabit throughtput on lan speeds(on a single machine, haven't tested multiple machines but I assume I'll have other hardware limitations prior to getting to XG, like the switch)

    It's more like the Software version is not utilising the hardware than downthrottling. 
    I didn't expect for it to have THAT much difference, but it seems that's the case.

    You could add some RAM, it will help, although it won't 200mbit help!
    Just fyi, I have an HP Proliant DL360 G6 with 2x 4core Xeons, 32gb RAM, 2x SAS drives(raid1). Sophos is run as a VM inside Proxmox with it's own LAN and WAN cards(separate from proxmox's LAN). Also I have 4 containers and 2 other VMs.
    Sfos is set with 4cores from the CPU and 4gb ram and works like it should. 

    It may sound like an overkill, but this kind of server is pretty cheap and the power consumption is not that big(about 160-180w on medium demands). Actually with the requirements I have, I don't think I can ever utilise the server full.

    Alternate solution is a medium sized pc(4core) with 4gb ram and an SSD connected at SATA3 port. You only have to connect one extra lan card(assuming the pc already has one, which most if not all do) and bam. You could get away with 150-170€ on a refurbished one. 

Reply
  • Like I and  noted, there's no way the Software is downthrottling. I have a live example on my server which started with 40/4mbps upgraded to 60/20 and now 200/200. Throughtput is full on internet speed and gigabit throughtput on lan speeds(on a single machine, haven't tested multiple machines but I assume I'll have other hardware limitations prior to getting to XG, like the switch)

    It's more like the Software version is not utilising the hardware than downthrottling. 
    I didn't expect for it to have THAT much difference, but it seems that's the case.

    You could add some RAM, it will help, although it won't 200mbit help!
    Just fyi, I have an HP Proliant DL360 G6 with 2x 4core Xeons, 32gb RAM, 2x SAS drives(raid1). Sophos is run as a VM inside Proxmox with it's own LAN and WAN cards(separate from proxmox's LAN). Also I have 4 containers and 2 other VMs.
    Sfos is set with 4cores from the CPU and 4gb ram and works like it should. 

    It may sound like an overkill, but this kind of server is pretty cheap and the power consumption is not that big(about 160-180w on medium demands). Actually with the requirements I have, I don't think I can ever utilise the server full.

    Alternate solution is a medium sized pc(4core) with 4gb ram and an SSD connected at SATA3 port. You only have to connect one extra lan card(assuming the pc already has one, which most if not all do) and bam. You could get away with 150-170€ on a refurbished one. 

Children
No Data