Low throughtput on Agent-based resources compared to Agentless.

Hello!

While doing a basic HTTP speedtest you can see the throughput of the Agent-based resources is considerably low compared to an Agentless resource. Is there a reason for that?

Latency and bandwidth aren't an issue since both tests were done over local network through a local ZTNA gateway. (I'm using a ZTNA ESXi Gateway on Proxmox, not ZTNAaaS.)

This is something I've noticed while doing some heavy file transfers over SSH - and moving some data over HTTP too.

It seems the bandwidth is limited to around ~200Mbit/s for Agent-based resources, indifferent if its TCP or UDP resources.

Comparing SSH, while doing file transfers over Agent-resource the throughput never passes 200 Mbit/s, meanwhile on the same host I can get gigabit while connecting directly.

Thanks!



Added TAGs
[edited by: Raphael Alganes at 5:54 AM (GMT -7) on 5 Sep 2024]
Parents
  • The question is, if you have the same performance with SSLVPN or other VPN services. 

    Overhead in VPN solutions are also impacting ZTNA and lower speed in that term. 

    Agentless will give you no overhead for encrypting the entire packet, its only the https part. 

    __________________________________________________________________________________________________________________

  • The question is, if you have the same performance with SSLVPN or other VPN services. 

    Using SSLVPN with Sophos Connect gives the same throughput (~200 Mbit/s)

    Meanwhile with OpenVPN Connect + DCO gives ~700 Mbit/s of throughput.

    I've gave 8 cores to the ZTNA VM, I'll do some testing now to see if it improves.

    Thanks for the answer!

    EDIT: Allocating more cores doesn't improve throughput, it seems a single connection can use only a single core.


    If a post solves your question use the 'Verify Answer' button.

    Ryzen 5600U + I226-V (KVM) v21 EAP @ Home

    Sophos ZTNA (KVM) @ Home

Reply
  • The question is, if you have the same performance with SSLVPN or other VPN services. 

    Using SSLVPN with Sophos Connect gives the same throughput (~200 Mbit/s)

    Meanwhile with OpenVPN Connect + DCO gives ~700 Mbit/s of throughput.

    I've gave 8 cores to the ZTNA VM, I'll do some testing now to see if it improves.

    Thanks for the answer!

    EDIT: Allocating more cores doesn't improve throughput, it seems a single connection can use only a single core.


    If a post solves your question use the 'Verify Answer' button.

    Ryzen 5600U + I226-V (KVM) v21 EAP @ Home

    Sophos ZTNA (KVM) @ Home

Children
No Data