Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

PPPoE connection on XGS 2100 SFOS 19.0.0 GA-Build31 - slow page loading

Hi, 

I have problem with pppoe connection which I don't know how to solve 

MTU 1492

MSS 1452

no web policy

no ips

no DoS

tried changing port (on port 2 connection was terrible)

Problem is that pages are loading slow, after I press "enter" on url nothing happens for 10 seconds and then it start to looking for page. I checked on multiple pc's, diferent browsers and directly plugged to lan port (without other clients).  Internet speed is about 200 mbps faster on ISP equipment. Behind XG I get around 350 download and 200 upload. 

Maybe this has to do something with dns but I don't know how to troubleshoot.

Thanks. 

Carlo



This thread was automatically locked due to age.
  • Hi Carlo 

    Can you check if the status for DNS is resolving properly from GUI with Test lookup ?

    Please go Configure -->Network -->DNS-->DNS Configuration, click on Test  Name lookup and add sophos.com click the Test connection?

    Have you checked the issue with mss as per the below command from CLI?

    console> set network mtu-mss Port2 mtu 1492 mss 1412

    Thanks 

    "Sophos Partner: Networkkings Pvt Ltd".

    If a post solves your question please use the 'Verify Answer' button.

  • After I execute that command I cannot browse internet any more. Need to return to old settings 1492/1444

  • does this mean something? 

  • Hi Carlo 

    Please check the status for the below commands 

    system appliance_access show 

    system firewall-acceleration show

    Thanks 

    "Sophos Partner: Networkkings Pvt Ltd".

    If a post solves your question please use the 'Verify Answer' button.

  • console> system appliance_access show
    Appliance access disabled.
    console> system firewall-acceleration show
    Firewall Acceleration is Enabled in Configuration.
    Firewall Acceleration is Loaded.
    

  • Hi Carlo 

    can you disable firewall acceleration and check website loads ?

    Thanks

    "Sophos Partner: Networkkings Pvt Ltd".

    If a post solves your question please use the 'Verify Answer' button.

  • Since when you identified the issue, any change done on upstream router and caused the issue?

    May be live session is required to generate proper  logs and investigate the issue along with packet flow from Sophos firewall 

    Have you raised support case ?

    Thanks

    "Sophos Partner: Networkkings Pvt Ltd".

    If a post solves your question please use the 'Verify Answer' button.

  • Hi Carlo 

    Please check if there is no issue with mss too as tcpdump you shared not having enough information 

    console> set network mtu-mss Port2 mtu default  mss 1380 

    Please revert the old settings if no change is found 

    Aslo, check the interface negotiation 100FD or 100HD ,you may also check if there is any negotiation issue between WAN or LAN with the next-in-line device.

    Open Console go to Option 4 and type ethe command

    console > system dia uti band       "press 'u' twice"

    Check if there is any error's E/S  (error/second)

    If so then lower the link speed.

    Also, another step provide us the output of the command;

    Console> sh net interfaces

    Thanks 

    "Sophos Partner: Networkkings Pvt Ltd".

    If a post solves your question please use the 'Verify Answer' button.

  • Hi Carlo 

    Please check SSL/TLS Inspection logs as well and share the output 

    Thanks 

    "Sophos Partner: Networkkings Pvt Ltd".

    If a post solves your question please use the 'Verify Answer' button.