This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Slow downloads on smartphones connected over AP

Hi,

we have a WiFi running for our smartphones mainly to update Android and apps. WiFi is offered through an AP55. Only smartphones can connect based on their MAC address. There is an own firewall rule for these connections with the following options active: HTTP scanning, block Google QUIC, detect zero day malware with Sandstorm, Scan FTP.

Unfortunately downloads are very slow. App updates take a long time and Android updates are canceled at a certain point by the smartphone itself.

As all updates are done over secure socket layer protocol and HTTPS scanning is not active I wonder what could be the reason. I checked the IP addresses that are used during update and always got to https://r3---sn-h0jeened.gvt1.com/ and https://r4---sn-h0jeened.gvt1.com/ so I excluded gvt1.com from HTTPS scanning, malware scanning and sandstorm. But also this showed no improvement on download speed.

Currently I wonder if the throughput of the AP55 is that slow?

 

Does anybody have any suggestions? Thanks.



This thread was automatically locked due to age.
  • manbearpig said:

    Please delete your Wireless Network and recreate it. 

    Unfortunately that doesn't help. The screenshot shows a test Wifi I've created last week, running SFOS 17.1.1 MR1.

  • Well, AP55 and WiFi have been created with the current SFOS 17.1.1 MR-1 so was it really fixed in 16.05???

    How can I recreate without configuring everything from the beginning?

  • Oh - Maybe i am wrong? Try to change the MTU Size on GUI. 

    I do not have access to a XG right now, so i cannot check the CLI for a Console switch. 

    But "from which" Firmware did you upgrade? As far as i know, this can only happen, if you used an old firmware and upgrade to V17.X 

    You should be able to change the MTU Size. The Problem is, i did not saw those issue for quite a while (2 years, since it was fixed in V16.05 ..) 

  • MTU for wireless interface can't be changed (on GUI)

  • This should be 1500 after recreation. I am quite sure. Checked another appliance right now. There is every Wireless Network created with 1450. 

    So i would highly assume, if you delete all network attached to this AP and recreate it, it should work fine. 

  • Why should it be ok after recreating when it was already created with the current firmware?

    What if I create an additional wifi network which creates an additional wireless interface? Should this have an MTU of 1500 right now (without deleting and recreating the other networks)?

  • The MTU Size (1450) is written in der Database. 

    So can you explain the history of your current installation? Because we dont change such thing with a firmware update. Basically the appliance should create everything new with the correct value (1500). 

    But dja already explained, it is not. So i have to assume, that the appliance does not allow to create 1450 and 1500 on one access points (which is clearly correct, because this would cause a real mess). 

    So basically if you delete everything from the wireless protection and maybe disable and enable the wireless protection, the new created wireless network should work fine. 

    You could also go with the Sophos Support. I could be possible to change the MTU Size via database, but i would not do that. 

    tbh, recreating wireless protection is a 5-10 minute task. 

  • The appliance was first installed in february 2018 with SFOS 17 and was directly updated to 17.0.5-MR5. It has been updated to 17.1.1-MR1 about 5 weeks ago. WiFi with AP55 was set up about 3 weeks ago. So where comes MTU 1450 from when it was fixed in 16.05?

  • I cannot tell you, how this can happen. 

    I already checked three appliances right now. All Wireless Networks are correct there. 

    And this is the first time since 2 years, where i could find such an issue. 

     

    Found some threads about this. 

    https://community.sophos.com/products/xg-firewall/f/sophos-xg-firewall-general-discussion/76768/unacceptable-guest-wifi-performance-regular-wifi-is-ok

     

    Also interesting is the initial firmware. You updated it "directly to MR5". From which version? 

  • manbearpig said:

    So i have to assume, that the appliance does not allow to create 1450 and 1500 on one access points (which is clearly correct, because this would cause a real mess). 

    Tested again and you're right. I've created a new Wireless Network, it has a MTU size of 1500. Then I assigned this new Wireless Network to an existing AP, now it has a MTU size of 1450.

    We've also would prefer to just change the values, instead of re-creating several Wifi networks...

    PS: We're coming from SFOS 15. It has been a loooong way. ;)