Hi All,
I have a ticket open with Sophos support for this but thought maybe the community can chip in too.
We have XG430s on our edge at our core and MPLS WAN links to our 8 sites and Cisco switches at our sites. Everything is working well.
Running SFOS 17.0.1 MR-1
However, when a new device connects to our network, either wired or wifi, it experiences a 2 minute delay before accessing the internet. I have a tcpdump showing the XG receives the packets and thinks that it has passed them on, but the wireshark capture from my ISP shows no activity for just over 2 minutes, and then there is activity.
I am using a class of device with a very simple XG rule applied to it - no IPS or scanning or malware detection or user lookup or ANYTHING AT ALL!
Once the device is known to the firewall it behaves fine.
If I take the device off the network for a couple days (I am yet to determine precisely this time range) the next time it's on the network it gets the 2 minute delay again.
So I've just sent Support the ISP wireshark capture and they have responded saying they want to do some testing and believe mss values are something to do with it. I don't know if I believe mss values are anything to do with this at all.
I can only think it's something within the firewall.
Any thoughts/comments welcome
This thread was automatically locked due to age.