Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

QoS issues (again)

.Hello @all!

So I have asked in the past a few questions about QoS, but I had a more complicated setup with two WANs and additionally the second was a bonding between an ADSL line and a 4G+ sim card, which was nor really steady regarding the bandwidth

Time went by and I finally have a decent FTTH connection (500/50)

Now the never-ending question: When I perform a speedtest I get a result of 508 down / 53 up

What I want is to limit my whole network to 495 down/ 49 up

I went to system services and created a Traffic shaping rule as follows

Then in Firewall rules I created a top firewall rule and set as source zone my LANs/VLANs and Destination zones WAN.

In this rule I set Shape Traffic to the traffic shaping rule above

I run a command line speedtest from a linux machine and this is what I get


Speedtest by Ookla

Server: LANCOM LTD - Athens (id: 12031)
ISP: FORTHnet SA
Idle Latency: 2.97 ms (jitter: 0.34ms, low: 2.83ms, high: 4.02ms)
Download: 292.54 Mbps (data used: 251.7 MB)
6.49 ms (jitter: 1.77ms, low: 3.61ms, high: 14.59ms)
Upload: 46.91 Mbps (data used: 21.8 MB)
3.09 ms (jitter: 0.31ms, low: 2.55ms, high: 4.53ms)
Packet Loss: 0.0%

Upload Speed is not exactly what I want but I don't mind.

But download speed is a far cry from 495Mbps

Funny thing is that if I change the download limit from 62000 to say, 70000, I get the exact speed from speedtest

Now I turn off the firewall rule and immediately run another speedtest

Speedtest by Ookla

Server: HYPERHOSTING - Athens (id: 5377)
ISP: FORTHnet SA
Idle Latency: 2.40 ms (jitter: 0.55ms, low: 1.71ms, high: 3.14ms)
Download: 408.47 Mbps (data used: 490.1 MB)
30.79 ms (jitter: 1.59ms, low: 3.77ms, high: 40.38ms)
Upload: 51.28 Mbps (data used: 23.9 MB)
44.51 ms (jitter: 8.94ms, low: 11.40ms, high: 301.76ms)
Packet Loss: 0.0%

My kids are downloading something from PS4 at the moment so not the full 500Mbps speed but still..

I have created another traffic shaping rule with the exact same numbers but this time instead of individual I set it to shared.

I get the exact same results: Setting download bandwidth to 62000 I get a speed of 300. Changing again to 70000 I get no increase.

Disabling the rule gets me back to 400+

Can someone explain what is going on?



Edited TAGs
[edited by: Erick Jan at 8:09 AM (GMT -7) on 20 Sep 2024]
  • Oh, crap..

    12th Gen 4xi226-V 2.5G Intel Firewall Mini PC N100 DDR5 4800MHz Fanless Soft Router

    This is what it says in the description. The BIOS I assume would have legacy (not 100% certain, though), but the network cards are 226. Are those not supported yet?

    But I assume there is always the option to install proxmox and create XG as a VM, right?

     
    Sophos XG Home Licence.

    Machine: Checkpoint 3100 appliance (Intel Atom C2558 CPU, 6GB Ram, 250GB sata SSD)

  • Correct on both counts.

    Ian

    XG115W - v20.0.2 MR-2 - Home

    XG on VM 8 - v21 GA

    If a post solves your question please use the 'Verify Answer' button.

  • Thanks again, Ian!

     
    Sophos XG Home Licence.

    Machine: Checkpoint 3100 appliance (Intel Atom C2558 CPU, 6GB Ram, 250GB sata SSD)

  • Hello  ,

    The above traffic shaping policy (Home_QoS) which you have configured is of type "limit" instead of "guarantee". It means it can go up to configured value but not giving any minimum guarantee.

    Could it be possible to try following configuration and check it once?

    Rule type: Guarantee

    Upload bandwidth: 6000 to 6250

    Download bandwidth: 59000 to 60000

    I presume Total available WAN bandwidth setting is still 68500 and Enforce guaranteed bandwidth is disabled.

    Regards,

    Sanket Shah

    Director, Software Development, Sophos Firewall

  • Hello  !

    I cloned the rule (because you can't edit and change to guarantee), used the numbers you said and applied the policy on my rule.

    I then run the speedtest.

    Fo upload I got 48Mbits, which seems about right. (the 6000 min guarantee)

    For download I was limited again by the CPU (as we established with Ian). I got about 260Mbits but observing top from console, I saw that cpu1 was hitting 99,6% utilization.

    My new appliance is on the way. It should arrive in about 10 -15 days. When I get it and set it up (I need to install proxmox and virtualize XG since the hardware is not supported), I will get back here with the results I will be getting with the new CPU (Intel N100).

     
    Sophos XG Home Licence.

    Machine: Checkpoint 3100 appliance (Intel Atom C2558 CPU, 6GB Ram, 250GB sata SSD)

  • Hello again, guys!

    I just wanted to give a quick update regarding this topic.

    I replaced my old appliance (which had an Atom C2558) with a new one with an Intel N100.

    I am happy to report that the new CPU is very comfortable and QoS works as expected.

    I would like to thank you again for your help!

    Have a great day!

     
    Sophos XG Home Licence.

    Machine: Checkpoint 3100 appliance (Intel Atom C2558 CPU, 6GB Ram, 250GB sata SSD)