This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

IPSec Site-to-Site and SSL-VPN abysmal performance

Hello,

I've never had really good performance in IPsec S2S, and it hasn't really be a bother. But, since times of home office, this is becoming increasingly important.

We own a SG125, which should more than cover our needs: 20 users in total, mostly some 15 VPN connections and one S2S tunnel (to free version).

However, even on lightest of days, with zero SSL-VPN connections, I have abysmal performance: not more than 10Mbit/s upload or download. The connection in the upload case (remote site to company site) is 25Mbit - limited by the upload-speed on the remote-site. Download speed at the company site is at least 50Mbit.

SSL-VPN is also very slow. Things like opening a folder over SMB, copying files, it all goes often in KB/s speeds.

Opening folders is sometimes real pain. It does matter what folders contain, but still. Copying alone should be faster.

I also did speedtests on both sides, and here I get full speeds.

Am I doing something wrong or is the firewall simply "old"?



This thread was automatically locked due to age.
Parents
  • Hallo guys,

    I'm not a fan of the 125 for 20 people in high-usage situations.  I suspect that the real problem here is that the 125 is overwhelmed by so much SSL VPN activity and that the IPsec site-to-site is not an issue.  I would fist try to replace the resource-intensive SSL VPN remote access with L2TP/IPsec or (my preference) the Sophos Connect client with IPsec remote access.

    If you're considering a faster internet connection, I would consider moving up to an SG 135 as it has a processor that's almost 50% faster and has twice the number of cores.

    If you're considering 500Mbps, I would consider a software license for 25 users and a small server with a 4-core-or-more processor that's 3.5GHz or faster.

    Any better luck after switching from SSL VPN remote access?

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
Reply
  • Hallo guys,

    I'm not a fan of the 125 for 20 people in high-usage situations.  I suspect that the real problem here is that the 125 is overwhelmed by so much SSL VPN activity and that the IPsec site-to-site is not an issue.  I would fist try to replace the resource-intensive SSL VPN remote access with L2TP/IPsec or (my preference) the Sophos Connect client with IPsec remote access.

    If you're considering a faster internet connection, I would consider moving up to an SG 135 as it has a processor that's almost 50% faster and has twice the number of cores.

    If you're considering 500Mbps, I would consider a software license for 25 users and a small server with a 4-core-or-more processor that's 3.5GHz or faster.

    Any better luck after switching from SSL VPN remote access?

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
Children
No Data