On my home box I updated to 9.306 and can see the update changed the MTU on my Separate Zone Guest Network to 1450; I haven't been able to test performance.
On our production network I'm not going to update until there is a real fix. All I've done on 9.305 was change the MTU of the Separate Zone Networks to 1280 and the performance increased to near original speeds. The problem now is that Lync will not connect over WiFi. If I change it back to 1500 Lync will connect but the connection is so slow it is unusable. My guess would be there are other applications which won't function correctly at 1280.
The one work around we were able to do was change the wireless card MTU to 1280 so it would match the Sophos MTU of 1280 and then Lync was able to connect and function, but I'm not about to do that for every wireless device on our network.
CTO, Convergent Information Security Solutions, LLC
https://www.convergesecurity.com
Sophos Platinum Partner
--------------------------------------
Advice given as posted on this forum does not construe a support relationship or other relationship with Convergent Information Security Solutions, LLC or its subsidiaries. Use the advice given at your own risk.
On my home box I updated to 9.306 and can see the update changed the MTU on my Separate Zone Guest Network to 1450; I haven't been able to test performance.
On our production network I'm not going to update until there is a real fix. All I've done on 9.305 was change the MTU of the Separate Zone Networks to 1280 and the performance increased to near original speeds. The problem now is that Lync will not connect over WiFi. If I change it back to 1500 Lync will connect but the connection is so slow it is unusable. My guess would be there are other applications which won't function correctly at 1280.
The one work around we were able to do was change the wireless card MTU to 1280 so it would match the Sophos MTU of 1280 and then Lync was able to connect and function, but I'm not about to do that for every wireless device on our network.
CTO, Convergent Information Security Solutions, LLC
https://www.convergesecurity.com
Sophos Platinum Partner
--------------------------------------
Advice given as posted on this forum does not construe a support relationship or other relationship with Convergent Information Security Solutions, LLC or its subsidiaries. Use the advice given at your own risk.
Apparently they switched to a different tunneling scheme for the "separate zone" function in 9.3xx and that is the root of the issue, as best I can tell.
CTO, Convergent Information Security Solutions, LLC
https://www.convergesecurity.com
Sophos Platinum Partner
--------------------------------------
Advice given as posted on this forum does not construe a support relationship or other relationship with Convergent Information Security Solutions, LLC or its subsidiaries. Use the advice given at your own risk.