Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Poor TCP Download speed (Virtualized Sophos XG)

Hi,

I'm facing a strange issue that I am not sure how to debug/improve. I'm using a virtualized Sophos XG on a proxmox server. WAN is connected to a 2.5Gb capable ethernet, but ISP provides only 1Gb symetrical.

What I see is :
- iPerf3 with UDP is yielding 1Gbps download speed (which I'm happy with obviously)
- iPerf3 TCP yield only 200Mbps

I have done the following for now (if only to test):
 - Deactivate IPS and DoS/Spoof protection
 - Set the WAN speed in my Traffic Shaping Setting to the correct 1Gbps
 - Double checked MTU are all at 1500 which is what is expected by my ISP
 - Check CPU usage, it never goes above 10%. Memory caps at around 50%.

My testing nodes are all in a VLAN that has 1 single Firewall rule : ALLOW ALL. This rule is number 2 on the list, and I run around 40 rules.

Is there anything else I can do to test this/debug this ?

Note i have observed a significant amount of Invalid Traffic in my log. I have read other posts suggesting to disable the logging but just bringing that up in case it is relevant her.



This thread was automatically locked due to age.
Parents Reply
  • Hi,

    KBA one is what I was referring to in my post.

    I have done : Deactivate IPS, remove DoS and Flood protection, set Trafic Shaping setting to the appropriate value, and CPU usage is indeed low.

    The only one i havent tried is setting the MTU as doing so in the past has resulted in networking wide instabilities. Having said so, a value of 1500 seems about right no ?


    Regarding KBA 2, what has DNS to do with any of this ? It's an iperf3 command to an IP Address. No DNS involved.

    Thanks,

Children