Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Sophos Connect - slow and freezing connections for SMB and RDP

I'm using Sophos XG 4500 v19 and we have noticed that connections to SMB servers when using Sophos connect remote access with default IPSEC profile are slow and unresponsive.

DoS protection is off  and we are not using traffic shaping.

Any Ideas ?



This thread was automatically locked due to age.
Parents
  • Hi Guys, I have a weird issue where my remote access users (Sophos Connect IPsec) are getting slow speeds all of them maxes out at 20mb up/down. We have a 1gb link at our offices and a lot of the users has at least 200mb connection

    We don't have any Qos or Traffic shaping configured and also no IPS 

    I have also disabled the ipsec-acceleration and the firewall-acceleration with no improvements 

    The ipsec one only helped for pages taking long to load.

    Has anyone come across this issue before? 

Reply
  • Hi Guys, I have a weird issue where my remote access users (Sophos Connect IPsec) are getting slow speeds all of them maxes out at 20mb up/down. We have a 1gb link at our offices and a lot of the users has at least 200mb connection

    We don't have any Qos or Traffic shaping configured and also no IPS 

    I have also disabled the ipsec-acceleration and the firewall-acceleration with no improvements 

    The ipsec one only helped for pages taking long to load.

    Has anyone come across this issue before? 

Children
  • Yes I'm still dealing with this (or similar). Ours is faster (around 25-35mbs on average) with a 500mbs connection at the office and 70mbs at the client side. I'm on macOS and have been trying different vpn clients in case that's the issue. The built-in Mac client connects but dns doesn't work because MacOS won't allow me to adjust the service order of IPSEC (Cisco) for some reason. I can't get any other client app to establish a connection at all. Been checking back here for a while now hoping someone came up with something.

    I'd also like to know if, because of my 70mbs connection, if 25-35 as good as I should expect. Does IPSEC generally cut speed by half?

    Thanks,

    Jeff

  • Sorry for the delay in response, but I have had a discussion with Sophos Support about this and they dont seem to have a fix for this. Not sure if you maybe got it sorted but we still have this issue

  • Jeff, My customer with an XG210 and a Gig internet connection can't download from file server (remotely) over VPN any faster that 2-3Mbps, so how for the love of cheeze-whiz are you getting 25-35?  That's something that Sophos support was never able to help me resolve. smh.

  • Everything off I can turn off for VPN traffic, the VPN firewall rule near the top (just under my phone rules). 

    Also, a recent game changer as been switching from IPSec to SSL. My speeds jumped up 10-fold. There's a couple people with cruddy service at their homes, so they're out of luck. Most most users are now have speeds in the 100s (I have GB at home and I'm anywhere from 350-450mbps).

    At first users to annoyed at changing how they connected (again) since we had just switched from as UTM a few months ago. The annoyance stopped when they saw how fast they were transferring files.

    Thanks,

    Jeff