3CX DLL-Sideloading attack: What you need to know
I'm using Sophos XG 4500 v19 and we have noticed that connections to SMB servers when using Sophos connect remote access with default IPSEC profile are slow and unresponsive.
DoS protection is off and we are not using traffic shaping.
Any Ideas ?
For users reporting this, please share your Case ID, so this issue can be brought to GES with a higher priority.
In the meantime users that remain on v19 and using XGS hardware, can you check if IPsec-Acceleration is enabled?
console> system ipsec-acceleration showIPsec acceleration status: turned on
If it’s, please disable
console> system ipsec-acceleration disable
This is not meant to be a solution, cases will still need to be created either if it fixes it or not.
turning off acceleration seems to work. Large files can now be opened at expected speed again. Thanks a lot. Can we expect a change or update here?
Did you have the issue with SSLVPN or Ipsec?
Issue with IPsec
Hi, case ID sent.Issue is only with IPSec, not SSL.Best regards.
IPsec acceleration status: turned on
Thank you for the Case ID, I have replied to your DM.
This helps with IPsec issues - thanks a lot
Now IPSec runs without performance issues.
I can also attest that disabling ipsec-acceleration fixed SMB browsing/folder loading issues with a client running XGS2100 and Sophos Connect with IPSec VPN.
I am so glad I stumbled on this thread. I just spent the day pulling what's left of my hair out trying to figure out why SMB was almost unusable but other protocols were fine.. I did these steps and they seem to have done the trick