Slow Throughput after installing v18 EAP

Hi,

I upgraded from v17.5.8 to v18 EAP about a week ago and noticed a drop in performance and an increased RAM usage.

I do have a XG115 rev2 Appliance installed with the Software  Image and a Home Use License.

My Internet connection is 100/40.

With version 17.5.8 I was able to reach about 80 to 90 Mbit download (I already expected more from the hardware)

After the Upgrade I only reach about 50 to 60 Mbit download. There is no DPI or webfiltering activated and it doesn't matter if i activate IPS or not.

SSL/TLS Inspection is turned on but there are not any rules.

Are there any tweaking options for the software version of Sophos XG running on a HW Appliance?

Thank you!

  • Hi,

    I've retest it on V18 EAP1 Refresh1, throughput still the same as v18, which is way slower than v17.5.8. I've decided to go back to v17.5.8 just to do some testing again, because i through could be something wrong with my hardware, but the throughput difference still high.

    Here's an CPU Usage graph from v17.5.8, while using all my WAN download throughput limit, 240-260 mbit/s. With IPS on generalpolicy.

     

    Here's on v18 EAP 1 Refresh 1. You can see the CPU spike at 8:30, that's when i decide to try download centos 8, throughput limit at it has 130mbit/s

     

     

    I didn't take any pictures, but for fun i've decide to make a VM of v18 EAP1, with 4 cores/6GB ram(Host => Ryzen 1700, 32GB ram), while on v17.5.8 I could get gigabit speeds on it (Using VirtiO Drivers i could get aroung 1.2 - 1.4 Gbit/s), on v18 the max speed i would get has aroung 480-510 mbit/s on iperf3.

     

    Thanks,


    If a post solves your question use the 'Verify Answer' button.

    Ryzen 5600U + I226-V (KVM) v20 MR1 @ Home

    XG 115w Rev.3 8GB RAM v19.5 MR3 @ Travel Firewall

  • Could you please verify the used drivers in V18? 

    Check please via ethtool of each interface. 

    __________________________________________________________________________________________________________________

  • SFVH_SO01_SFOS 18.0.0 EAP1-Refresh1# ethtool -i Port2
    driver: igb
    version: 5.3.5.20
    firmware-version: 1.2.1
    expansion-rom-version:
    bus-info: 0000:01:00.1
    supports-statistics: yes
    supports-test: yes
    supports-eeprom-access: yes
    supports-register-dump: yes
    supports-priv-flags: no


    SFVH_SO01_SFOS 18.0.0 EAP1-Refresh1# ethtool -i Port1
    driver: igb
    version: 5.3.5.20
    firmware-version: 1.2.1
    expansion-rom-version:
    bus-info: 0000:01:00.0
    supports-statistics: yes
    supports-test: yes
    supports-eeprom-access: yes
    supports-register-dump: yes
    supports-priv-flags: no


    If a post solves your question use the 'Verify Answer' button.

    Ryzen 5600U + I226-V (KVM) v20 MR1 @ Home

    XG 115w Rev.3 8GB RAM v19.5 MR3 @ Travel Firewall

  • Can you please show us the output of ethtool without -i ?

    __________________________________________________________________________________________________________________

  • SFVH_SO01_SFOS 18.0.0 EAP1-Refresh1# ethtool Port1
    Settings for Port1:
            Supported ports: [ TP ]
            Supported link modes:   10baseT/Half 10baseT/Full
                                    100baseT/Half 100baseT/Full
                                    1000baseT/Full
            Supported pause frame use: Symmetric
            Supports auto-negotiation: Yes
            Supported FEC modes: Not reported
            Advertised link modes:  10baseT/Half 10baseT/Full
                                    100baseT/Half 100baseT/Full
                                    1000baseT/Full
            Advertised pause frame use: Symmetric
            Advertised auto-negotiation: Yes
            Advertised FEC modes: Not reported
            Speed: 1000Mb/s
            Duplex: Full
            Port: Twisted Pair
            PHYAD: 1
            Transceiver: internal
            Auto-negotiation: on
            MDI-X: off (auto)
            Supports Wake-on: pumbg
            Wake-on: g
            Current message level: 0x00000007 (7)
                                   drv probe link
            Link detected: yes

     

    SFVH_SO01_SFOS 18.0.0 EAP1-Refresh1# ethtool Port2
    Settings for Port2:
            Supported ports: [ TP ]
            Supported link modes:   10baseT/Half 10baseT/Full
                                    100baseT/Half 100baseT/Full
                                    1000baseT/Full
            Supported pause frame use: Symmetric
            Supports auto-negotiation: Yes
            Supported FEC modes: Not reported
            Advertised link modes:  10baseT/Half 10baseT/Full
                                    100baseT/Half 100baseT/Full
                                    1000baseT/Full
            Advertised pause frame use: Symmetric
            Advertised auto-negotiation: Yes
            Advertised FEC modes: Not reported
            Speed: 1000Mb/s
            Duplex: Full
            Port: Twisted Pair
            PHYAD: 1
            Transceiver: internal
            Auto-negotiation: on
            MDI-X: off (auto)
            Supports Wake-on: d
            Wake-on: d
            Current message level: 0x00000007 (7)
                                   drv probe link
            Link detected: yes


    If a post solves your question use the 'Verify Answer' button.

    Ryzen 5600U + I226-V (KVM) v20 MR1 @ Home

    XG 115w Rev.3 8GB RAM v19.5 MR3 @ Travel Firewall

  • I too had issues with EAP1 on a hardware XG135 with the software build.  I did just update to EAP1-Refresh1 and there is marked improvement in reliability and speed for me.

    With DPI on, no slow down.  Getting close to 200 down and 40 up.  Same as what I was getting on 17.5.8.  More importantly, the connection doesn't drop/reset every minute.

    I haven't switched on SSL inspection yet.  Will do that after watching how this does for the morning.

  • Hi all,

    I'm having speed issues as well with EAP1 and Refresh1. I get around 75mbit/s and with v17 I could easily reach > 200mbit.

    I've installed the SFW-Version in a KVM machine with virtio network devices.

    ethtool is showing something very interesting - although I don't know if this was the case in v17 as well:

     

    Settings for Port1:

    Supported ports: [ ]

    Supported link modes:   Not reported

    Supported pause frame use: No

    Supports auto-negotiation: No

    Supported FEC modes: Not reported

    Advertised link modes:  Not reported

    Advertised pause frame use: No

    Advertised auto-negotiation: No

    Advertised FEC modes: Not reported

    Speed: Unknown!

    Duplex: Unknown! (255)

    Port: Other

    PHYAD: 0

    Transceiver: internal

    Auto-negotiation: off

    Link detected: yes

  • Hi,

     

    Do we have any news on this?

    Is this an issue with only a small percentage of people, or an miss-configuration issue from everyone that's having performance issues?

    Or it's a known issue on v18 EAP 1 ?

     

     

    Thanks,


    If a post solves your question use the 'Verify Answer' button.

    Ryzen 5600U + I226-V (KVM) v20 MR1 @ Home

    XG 115w Rev.3 8GB RAM v19.5 MR3 @ Travel Firewall

  • Could you try to change the adapters, just to be sure and reboot? 

    Which hypervisor do you use? 

    __________________________________________________________________________________________________________________

  • LuCar Toni said:

    Could you try to change the adapters, just to be sure and reboot? 

    Which hypervisor do you use? 

     

     

    Hi,

     

    I'm currently running v18 on bare-metal, with a Intel J1900 + 8GB RAM, with Intel 82576 2 Ports NIC.

    On bare metal I has able to get >240mbit/s  while not even using more than 45% of the CPU on v17.5.8, with v18 EAP 1 Refresh 1 the maximum i get is around 120-130mbit/s, while snort is using 100% of all 4 Cores, something that never happened on v17.5.8.

     

    The VM I've used to test the performance difference has on CentOS with KVM, using virt-manager to manage it. I've tested using VirtiO drivers and e1000e. Both gave me same throughput on the tests on v18.

     

    Thanks,


    If a post solves your question use the 'Verify Answer' button.

    Ryzen 5600U + I226-V (KVM) v20 MR1 @ Home

    XG 115w Rev.3 8GB RAM v19.5 MR3 @ Travel Firewall