Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

QoS issues (again)

.Hello @all!

So I have asked in the past a few questions about QoS, but I had a more complicated setup with two WANs and additionally the second was a bonding between an ADSL line and a 4G+ sim card, which was nor really steady regarding the bandwidth

Time went by and I finally have a decent FTTH connection (500/50)

Now the never-ending question: When I perform a speedtest I get a result of 508 down / 53 up

What I want is to limit my whole network to 495 down/ 49 up

I went to system services and created a Traffic shaping rule as follows

Then in Firewall rules I created a top firewall rule and set as source zone my LANs/VLANs and Destination zones WAN.

In this rule I set Shape Traffic to the traffic shaping rule above

I run a command line speedtest from a linux machine and this is what I get


Speedtest by Ookla

Server: LANCOM LTD - Athens (id: 12031)
ISP: FORTHnet SA
Idle Latency: 2.97 ms (jitter: 0.34ms, low: 2.83ms, high: 4.02ms)
Download: 292.54 Mbps (data used: 251.7 MB)
6.49 ms (jitter: 1.77ms, low: 3.61ms, high: 14.59ms)
Upload: 46.91 Mbps (data used: 21.8 MB)
3.09 ms (jitter: 0.31ms, low: 2.55ms, high: 4.53ms)
Packet Loss: 0.0%

Upload Speed is not exactly what I want but I don't mind.

But download speed is a far cry from 495Mbps

Funny thing is that if I change the download limit from 62000 to say, 70000, I get the exact speed from speedtest

Now I turn off the firewall rule and immediately run another speedtest

Speedtest by Ookla

Server: HYPERHOSTING - Athens (id: 5377)
ISP: FORTHnet SA
Idle Latency: 2.40 ms (jitter: 0.55ms, low: 1.71ms, high: 3.14ms)
Download: 408.47 Mbps (data used: 490.1 MB)
30.79 ms (jitter: 1.59ms, low: 3.77ms, high: 40.38ms)
Upload: 51.28 Mbps (data used: 23.9 MB)
44.51 ms (jitter: 8.94ms, low: 11.40ms, high: 301.76ms)
Packet Loss: 0.0%

My kids are downloading something from PS4 at the moment so not the full 500Mbps speed but still..

I have created another traffic shaping rule with the exact same numbers but this time instead of individual I set it to shared.

I get the exact same results: Setting download bandwidth to 62000 I get a speed of 300. Changing again to 70000 I get no increase.

Disabling the rule gets me back to 400+

Can someone explain what is going on?



Edited TAGs
[edited by: Erick Jan at 8:09 AM (GMT -7) on 20 Sep 2024]
  • Thanks for the screenshot. Never doubted that it works for you. It is just that for some reason it does not work for me..

    And after a few tests, I believe there is a possibility that it would not work for you, either, if your speed was above the one you have.

    What I mean:

    I performed a first test using your numbers. (Total 32500, guaranteed 30000, limit 31000)

    The results I get are similar to yours .. I got 204/44 - forgot to take a screenshot :)

    I then cut the numbers in half (Total 16000, guaranteed 15000, limit 15500).  Run a speedtest and download speed indeed was cut in half

    I then set the numbers at a quarter of yours (Total 8000, guaranteed 7500, limit 7800). Run a speedtest and again the speeds are cut at a quarter of your speeds.

    So everything from about 250Mbits and below works as expected so far. I then set once again the speeds at about double your numbers. (Total 60000, guaranteed 58000, limit 59000)

    And lo and behold, the speeds are not exceeding your numbers

    I am starting to believe that there is a bug and it won't let speeds go above about 250Mbits.

    And it is just a diabolical coincidence that your speeds don't exceed 250, so you have never experienced this issue.

    But of course this is purely hypothetical. I hope there is someone with speeds above 400 that can run a test (??)

     
    Sophos XG Home Licence.

    Machine: Checkpoint 3100 appliance (Intel Atom C2558 CPU, 6GB Ram, 250GB sata SSD)



    bad screenshot
    [edited by: ChriZathens at 7:23 AM (GMT -7) on 23 Sep 2024]
  • I previously had a 1000/50 link which maxed out the xg115w at around 600-700.

    XG115W - v20.0.2 MR-2 - Home

    XG on VM 8 - v21 GA

    If a post solves your question please use the 'Verify Answer' button.

  • Don't know then...

    Can't be sure. I can't understand why I am the only one having this issue.

    Is there perhaps any bug introduced lately that is causing that behavior?

    If there is anyone with the latest version kind enough to test with a connection faster than 400 Mbits, it would be great.

    At least I will be sure that the problem is only on my side (although I can't comprehend why this would happen only to me...)

     
    Sophos XG Home Licence.

    Machine: Checkpoint 3100 appliance (Intel Atom C2558 CPU, 6GB Ram, 250GB sata SSD)

  • Do you have ips enabled on the testing rule p, if so what are the settings?
    ian

    XG115W - v20.0.2 MR-2 - Home

    XG on VM 8 - v21 GA

    If a post solves your question please use the 'Verify Answer' button.

  • I did not even have a rule in place during the above tests.

    But just to make sure I enabled the rule now and got same exact results as the last speedtest screenshot (about 250down)

    The rule has no ips configured. It is just a simple rule. Source zones all my internal networks, destination zone WAN and from the rest of the settings I have nothing configured, no app control, no web filter, no ips, just trafiic shaping:

    The Home_QoS rule has the below settings:

    Perhaps it is worth mentioning that if I change Upload bandwidth to half of the above (3300), the upload speed is limited to half, as it should

    So once again the "low" numbers work as they should.

    Numbers that offer a download limit above 250Mbits are the ones that don't work

     
    Sophos XG Home Licence.

    Machine: Checkpoint 3100 appliance (Intel Atom C2558 CPU, 6GB Ram, 250GB sata SSD)

  • XG115W - v20.0.2 MR-2 - Home

    XG on VM 8 - v21 GA

    If a post solves your question please use the 'Verify Answer' button.

  • OK, here is mine

    Additionally let me share that for download speed in the traffic shaping rule, even if I put the max number 2560000, it still limits to 250Mbits 

    It is as if it will discard any number above 30000-35000 for download limit

     
    Sophos XG Home Licence.

    Machine: Checkpoint 3100 appliance (Intel Atom C2558 CPU, 6GB Ram, 250GB sata SSD)

  • A suggestion you might like to consider, your hardware is being maxed out. You could try running two or three speed tests at the same time from different devices and look at the diagnostic graphs.

    ian

    XG115W - v20.0.2 MR-2 - Home

    XG on VM 8 - v21 GA

    If a post solves your question please use the 'Verify Answer' button.

  • It has crossed my mind and now that you mentioned it, too, I gave it a try

    I run a windows app speedtest and a command line speedtest at the same time. During these tests I had the XG console running top.

    The tests combined did not exceed  280Mbits down while CPU usage did not exceed 58%.

    EDIT : Run again and CPU reached 72%. With only one test running it does not go beyond 60%

    Are there any other commands I can issue from the console to possibly get more accurate readings?

     
    Sophos XG Home Licence.

    Machine: Checkpoint 3100 appliance (Intel Atom C2558 CPU, 6GB Ram, 250GB sata SSD)

  • The cpu is a 4 core so unless you go into console and run top or similar you will never see what is happening.

    i did a deeper investigation into the cou, it is 11 years old model with in built nics, so probably you are seeing the best performance you will get.

    ian

    ian

    XG115W - v20.0.2 MR-2 - Home

    XG on VM 8 - v21 GA

    If a post solves your question please use the 'Verify Answer' button.