Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

XG135w with 12% packet loss on WAN interface over PPPoE in Japan (MTU 1454 / MSS 1407)

Hi, Guys 'n' Gals.

As the subject states, I installed an XG135w at a client site that is on Asahi Net (NTT backbone) with gigabit fibre. I'm in an unhappy situation where I have been unable to leave the box online because with Japan's state of emergency, basically the entire staff are working from home. As such, my questions and the information I can provide are full of holes. I forced them through five hours of downtime before I had to restore service with their existing VPN router.

I've set up a number of UTM devices in the past and the UTM units manage MSS automagically. With the XG, setting MTU to the required 1454 causes the interface config to complain that I need an MSS at least 48 bites lower than the MTU. OK, so I set MSS override to 1407, which by my calculations is the largest MSS. The connection to the service provider comes up, but when I ping 8.8.8.8, I see a consistent 12-13% packet loss. With the same ONU and Ethernet cables, the customer's other VPN router has zero loss.

My Googlefu has left me blank and I really don't know where to start with this. The client previously had an SG125 on that connection that worked without issue for years before it suddenly bricked (Intel SOC issue). So, I'm somewhat at a loss as to why an SG with UTM9 would work flawlessly and a new XG with newest firmware (as of yesterday) would see such high packet loss. Any suggestions on what I can check in the XG configuration would be most helpful. This is my first XG and the UI has yet to become intuitive.

Please note: I cannot at this time supply further information and I do not have access to the unit until the weekend.

Warmest regards,

trane



This thread was automatically locked due to age.
Parents
  • Hi  

    Sorry for the inconvenience caused!

    Did you open a service request with technical support? If yes, please share the service request number

    Is ISP works on PPPoE connection? What negotiation speed has been configured for WAN interface? Was it set to auto or configured manually?

    Did you check by changing the WAN interface to other XG physical port? What is your observation when you connect a single Laptop to LAN interface and try to ping public IP?

    Is it possible that you could initiate the ping from LAPTOP to LAN interface of XG firewall and public IP of the XG firewall and see if you are getting delay on both the ports?

    Regards,

    Keyur
    Community Support Engineer | Sophos Support
    Sophos Support VideosKnowledge Base  |  @SophosSupport | Sign up for SMS Alerts |
    If a post solves your question use the 'This helped me' link

  • Hi, Keyur.

    I didn't open a support request because I was not in a position to leave the unit online. It is offline, packed away in its box.

    Yes, the account is PPPoE. WAN is configured for auto negotiation.

    I did not try changing WAN interface to a different port. It did not occur to me that the port might be faulty on a brand new unit. I can try that on my next visit.

    I did not try pinging the WAN IP address, only remote IPs. I will also try the WAN IP.

    It'll be the weekend before I am able to get on-site again, I think. Once I have more information, I will revert.

    Thanks for the head start. Much appreciated.

    trane

Reply
  • Hi, Keyur.

    I didn't open a support request because I was not in a position to leave the unit online. It is offline, packed away in its box.

    Yes, the account is PPPoE. WAN is configured for auto negotiation.

    I did not try changing WAN interface to a different port. It did not occur to me that the port might be faulty on a brand new unit. I can try that on my next visit.

    I did not try pinging the WAN IP address, only remote IPs. I will also try the WAN IP.

    It'll be the weekend before I am able to get on-site again, I think. Once I have more information, I will revert.

    Thanks for the head start. Much appreciated.

    trane

Children
No Data