Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

How to achieve greater than 1Gbps on XGS116

I'm looking to utilize a 2Gbps symmetrical connection on an XGS116. Based on the specs, it should be able to handle 7.7Gbps, or 2.0Gbps with NGFW enabled. I've currently got the upstream CPE connected via a 10Gbps SFP+ module to a CS110-48P on its own isolated VLAN, then a LAG with two cables to the firewall. Yet speed testing with multiple clients seems to be hard limited to 1Gbps.

Shouldn't this be possible? If so, what am I doing wrong?



This thread was automatically locked due to age.
  • Hi,

    Please provide a drawing of your configuration.

    What you are seeing is the advertised specifications for each function of the firewall under ideal conditions, this is an industry standard approach to testing.

    I would be surprised if the XGS116 in a production environment can get much above about 700-800 Mb/s throughput.

    Ian

    XG115W - v20.0.2 MR-2 - Home

    XG on VM 8 - v21 GA

    If a post solves your question please use the 'Verify Answer' button.

  • LAG with 2x 1Gb/s cables to the firewall = 2 Gb/s effective speed for you? I don't think so.
    Maybe for (all) sessions you have in total via round robin...



    .
    [bearbeitet von: Quallensaft um 9:21 AM (GMT -8) am 9 Nov 2023]
  • I'm aware it's not as good as a 10Gbps link, but shouldn't it be better than 1Gbps? As I said, I'm running speed tests from multiple clients, so there are multiple sessions being used. I'm not concerned if one client can saturate the link.



  • Here's a basic diagram. There are of course more clients, but this shows what I'm trying to do.

    I'm sure the specs are tested under ideal conditions. However, I seem to be hard limited at exactly 1Gbps, with only the default network enabled and all security features turned off. I'm not sure how much more ideal you could get than that. But that being said, somehow it must be possible to route above 1Gbps if they were able to achieve it in testing. I just want to know how that somehow is.

  • Hi,

    thank you for the diagram. I suspect a bridge would be better than LAG VLANs?

    My thoughts.

    Ian

    XG115W - v20.0.2 MR-2 - Home

    XG on VM 8 - v21 GA

    If a post solves your question please use the 'Verify Answer' button.

  • Please also check if you have the right LAG mode (on booth sides):

    Don't look at the clients, just check your LAG (member) interfaces on the firewall -> diagnostics -> system graphs.
    On my firewall with LAG, I can see the traffic is nearly 50:50 on my LAG interface (as it should).