This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

New Home Build For 1g connection

Hello World,

I am about to build another PC to run Sophos home as my current hardware is severely outdated. im currently running Athlon XP. (dont laugh)

I can get a good deal combo for CPU and MOBO to support the AMD Ryzen 5 3400. 

My question is would this CPU running 6g of memory get me closer to achieving 1g speed? 

If not, does anyone have any experience and/or recommendation on what is the best hardware build for getting close to 1g speed?

I'm not married to AMD as I have no problems building a unit using Intel if it will get me better throughput.

Just looking to maximize throughput on this new build. 

Thanks for all responses



This thread was automatically locked due to age.
  • Hi Bobby,

    You will get >1Gbit/s throughput with the 3400G on Threat Prevention Traffic (IPS+AppCtrl+AV), but I'm not sure if you will get 1Gbit/s with SSL/TLS Decryption. (There are issues with AMD Ryzen on things related to encryption/decryption in v18)

    If your not doing SSL/TLS Decryption, then even a Intel G5400, a 2C/4T CPU can handle 1Gbit/s.

    But my recommendation if your going to decrypt your traffic, is go with Intel, or if you can, get a Ryzen 3300x instead of the 3400G, since It's a really good value CPU; And can handle 1Gbit/s of Threat Prevention with SSL/TLS Decryption. (I'm currently using it.)

    Thanks!


    If a post solves your question use the 'Verify Answer' button.

    Ryzen 5600U + I226-V (KVM) v20 GA @ Home

    XG 115w Rev.3 8GB RAM v19.5 MR3 @ Travel Firewall

  • Thanks for the response. I'm only doing ssl decryption on the DMZ and guest wireless. If the Ryzen 3300 can give me the same performance without any issues I will go with that. 

    However, you mention issues as it pertains to encryption / decryption. Can you give some examples? I dont want to purchase new hardware only to have issues. 

    Also, if I decided to go the Intel route what chip would you recommend besides the G5400? Just curious.

    Thanks for all responses.

  • However, you mention issues as it pertains to encryption / decryption. Can you give some examples? I dont want to purchase new hardware only to have issues. 

    There are a lot of issues, primarily with Ryzen Gen 1, which is the 1X00 Series and Gen 2 which is 2X00, there are some relates of both 3400G and 3400G also having issues; For some unknown reason anything related to encryption/decryption is absurdly slow.

    I'm talking about 200Mbit/s over a single x86 core at 3.8Ghz. but you will only suffer this issue while doing SSL/TLS Decryption - Interested enough the throughput with Threat Prevention is really high for those CPU's.

    Also, if I decided to go the Intel route what chip would you recommend besides the G5400? Just curious.

    Get a >7th Gen or above, primarily 4 Cores CPUs, one that I can recommend, (If you find used) is the I3-8100.

    If the Ryzen 3300 can give me the same performance without any issues I will go with that. 

    Yes, you will be able to do >1Gbit/s with SSL/TLS Decryption on the 3300X with a imix traffic. (I know this from personal experience.)

    Also,

    I'm only doing ssl decryption on the DMZ and guest wireless.

    Just to clarify this, how you will do decryption on your guest network? It's not possible to do it without importing the XG Certificate Authority on the client.

    Thanks!


    If a post solves your question use the 'Verify Answer' button.

    Ryzen 5600U + I226-V (KVM) v20 GA @ Home

    XG 115w Rev.3 8GB RAM v19.5 MR3 @ Travel Firewall

  • Thank you for the response. My guest wireless is really just devices at my home network that are untrusted so I have the cert installed on them. 

    Thank you for your response. I will purchase the 3300. I see a new one on Amazon for $90. 

    Again, thanks for your assitance. 

  • Just a reminder, the 3330X don't have graphics, so there are two ways to install XG on it, or you can put a graphics card and remove it after the installation (Sophos XG will boot without any issues - without a graphics card.), or get a motherboard such as the ASRock X470D4U.

    Thanks!


    If a post solves your question use the 'Verify Answer' button.

    Ryzen 5600U + I226-V (KVM) v20 GA @ Home

    XG 115w Rev.3 8GB RAM v19.5 MR3 @ Travel Firewall

  • Prism

    would the AMD Ryzen 3 3100 4-Core, 8-Thread or AMD Ryzen 3 3200G 4-Core Unlocked Desktop Processor with Radeon Graphics work just as good? I'm not seeing a lot of 3330X readily available.

    Again, thanks for all responses. 

  • It's better to get the AMD Ryzen 3100.


    If a post solves your question use the 'Verify Answer' button.

    Ryzen 5600U + I226-V (KVM) v20 GA @ Home

    XG 115w Rev.3 8GB RAM v19.5 MR3 @ Travel Firewall

  • Just wanted to say thanks for the recommendation. This build is exactly what i was looking for. I'm getting about 780mbs down and over 900mbs up. My old AthlonXP processor I was getting about 150mbs down and like 250mbs up. 

    Once again. Thanks for all the responses. I appreciate it.

  • That's awesome!

    One tip for even better throughput.

    SSH in your XG or open the Console from the Admin Page, and go to Option (4) which is Device Console.

    In there execute: "set ips search-method hyperscan".

    Hyperscan is a regex matching library from Intel, which is around 4x faster than ac-bnfa - that Sophos set as default on the Software Installations. This will increase your IPS throughput by around 3x in the Ryzen 3100.

    Thanks!


    If a post solves your question use the 'Verify Answer' button.

    Ryzen 5600U + I226-V (KVM) v20 GA @ Home

    XG 115w Rev.3 8GB RAM v19.5 MR3 @ Travel Firewall

  • will do. Again, many thanks