I have been struggling with my SG430's fiber connection to my ISP where we have purchased 1GBps throughput on a dedicated 10GBps port, with bandwidth policers. The SG is connected directly to a Cisco switch not 100 feet below me. I am using an Intel E10G SFP LR GBIC with a Sophos SG Series FlexiPort module. Machine is running 9.407-3The following services are active:
- Firewall
- IPS
- Network Visibility
- Wireless Protection with 10AP's
- Site to Site VPN (one connection)
- WAF
- ATP
Turning off IPS and ATP got me up to 215Mbps up and 300MBps down.
I have not configured QoS, and we have approximately 80 users with two devices (company issued and one personal device- 160 devices total, at least; 180 at most). My SG is probably not getting above 14% of its available 16G RAM, CPU hasn't gotten over 8% and it has only been in production for about 2 weeks, so nothing to report as far as log disk or data disk. I have made changes to match the MTU and port speeds on all the interfaces (Cisco in front and Cisco behind the SG). My port settings are 1000 full, no auto negotiation for the internal interfaces, and 1000 full, auto negotiation at the edge (more on this below). I have checked a couple of times with the carrier, and we should be getting about 820-900MBPS when I connect my laptop directly, up/down, but we are only pushing about 160 up/down through the UTM. That only improved after I noticed in the shell that my internal interface was advertising 1000M full auto, but when i logged into the shell, it was only set for 100M full auto negotiating. Changing it to 1000M Full no Auto Negotiation improved my bandwidth, but I am still way off my mark.
Lastly, when I tried to change the speed to 10000 and auto-negotiating settings through the GUI, I received the error message "The ethernet interface hardware object requires one of certain fixed strings for the speed attribute."
When a Sophos engineer tried to do the same remotely, he also received the same error message.
We currently have a case open with Sophos regarding the issue.
Questions:
- has anyone ever seen this issue or error before?
- am I required to reboot the SG after an MTU change?
- I have read that if I make setting interface changes through the shell, those changes are not committed after the SG reboots (and it will be rebooted, inevitably), is this true?As
As always, any help is appreciated. Thank you in advance!
This thread was automatically locked due to age.