Bandwidth meter for SD-WAN routes is unreliable.

Hello!

At first, I don't know if this is a known bug for the Sophos team, since I couldn't find It on the "Known Issues List".

The bandwidth meter for the SD-WAN routes doesn't show the correct bandwidth that went through each route. This is only an interface issue, the routing itself works as expected.

As an example I've created two rules, one with FQDN's and another with Application Objects, both does the same thing which is send OneDrive traffic to a high bandwidth link.

After downloading >12GB of data, both meters are showing only some megabytes of data went through those rules, looking over the Firewall logs it shows otherwise.

Thanks!

Parents
  • Hey Prism,

    SDWAN-route and Firewall stats reported are not comparable apple-to-apple. Routing is per-packet operation and only captures those packets stats which passes thru it. Firewall rule works in stateful manner. All request and reply (client to server and server to client) fall under same firewall rule. 

    Having said that, it is quite possible for these two meters to report different reading. For example, if asymmetric routing is configured. or SDWAN routing is configured only request direction, SDWAN-route will account only for the upload stats as downloads might be following a different SDWAN route (or other routes).

    Let us know if this is not the case in your observation.

    HTH

    Moheed

Reply
  • Hey Prism,

    SDWAN-route and Firewall stats reported are not comparable apple-to-apple. Routing is per-packet operation and only captures those packets stats which passes thru it. Firewall rule works in stateful manner. All request and reply (client to server and server to client) fall under same firewall rule. 

    Having said that, it is quite possible for these two meters to report different reading. For example, if asymmetric routing is configured. or SDWAN routing is configured only request direction, SDWAN-route will account only for the upload stats as downloads might be following a different SDWAN route (or other routes).

    Let us know if this is not the case in your observation.

    HTH

    Moheed

Children
No Data