Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Sophos Connect - slow and freezing connections for SMB and RDP

I'm using Sophos XG 4500 v19 and we have noticed that connections to SMB servers when using Sophos connect remote access with default IPSEC profile are slow and unresponsive.

DoS protection is off  and we are not using traffic shaping.

Any Ideas ?



This thread was automatically locked due to age.
Parents
  • Did you run your firewall with older firmware before and was performance OK there?

    Is this for all users or only some?

    We've once had SMB (no RDP) performance issues over VPN caused by software based file encryption on the SMB file server. This was not noticable in LAN, only VPN.

  • RDP via Sophos Connect VPN client seems to be OK on Windows but is disconnecting on Mac OS. SMB is slow both in Windows and Mac OS. I can't confirm if this was ok on the old firmware.

  • Can see the same behavior after upgrade to v19. we also have file servers behind a ipsec between two sophos xg with v19. after downgrade to 18.5.3 the performance is back.

  • can we compare the settings of the default "DefaultRemoteAccess" IPSec Policy, which is used for Remote Access in v18.5 with v19?

    Is it possible, that there is now default IPS or whatever enabled for the IPSec packets causing high delay and that this scanning was not active in v18.5?

    You could try disabling IPS and ATP for a moment and reconnect IPSec VPN.

    This is v18.5 MR3:

    DDon't have v19 running.

Reply
  • can we compare the settings of the default "DefaultRemoteAccess" IPSec Policy, which is used for Remote Access in v18.5 with v19?

    Is it possible, that there is now default IPS or whatever enabled for the IPSec packets causing high delay and that this scanning was not active in v18.5?

    You could try disabling IPS and ATP for a moment and reconnect IPSec VPN.

    This is v18.5 MR3:

    DDon't have v19 running.

Children