This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Sophos XG 105: hardware ISO performs betters than software ISO with home license on XG hardware? Is sophos limiting speeds when using home licenses on Sophos hardware?

Dear community,

I am testdriving a XG105 that I got from a friend who works at an IT company to test out the performance. I currently have a 200/200 fiber internet connection.

After installing the hardware ISO (HW-17.5.1_MR-1-347) and running the installation wizard, I got a speed result of 160Mbps with all protections enabled in the wizard.

However: after installing the software ISO (SW-17.1.4_MR-4-254) with a Home license and running the installation wizard with exactly the same protections enabled, I got a speed result of 30 Mbps.

How is this possible?

Has Sophos limited the speed of XG home installations on Sophos XG hardware?

(I remember that on an older UTM120 device there was NO speed difference between software and hardware installations of UTM and XG.)

 

[*-)]



This thread was automatically locked due to age.
  • I am using the software Home install on the latest firmware SFOS 17.5.0 GA running on a Dell Pentium 4 3.4GHz w 3MB RAM... I am seeing nearly wireline speed on speed tests I have 400Mb/s Down and 23Mb/s up service and seeing 480+Mb/s down and 24Mb/s up on the tests I have performed.

    I have one intel NIC on the MB and one cheap PCI based NIC on the system. Hardware acceleration is unavailable... My rules are fairly plain and simple however I do employ FQDN groups and have seen the avd process peg the CPU several times without warning and have yet to understand why that has happened randomly. Are there other settings under the hood we can look at??

     

    console> show ips_conf
    config stream        1
    config maxsesbytes        0
    config stdsig        1
    config qnum        10
    config maxpkts        8
    config disable_tcpopt_experimental_drops        0
    config enable_appsignatures        1
    var SIP_STATUS        enabled
    var IGNORE_CALL_CHANNEL        enabled
    var TCP_POLICY        windows
    var LOCAL_RULE        local.rules
    var DETECT_ANOMALIES        yes
    var TCP_BLOCK        block
    var SEARCH_METHOD        ac-bnfa
    config failclose        off
    config cpulist        0:1

    console> system hardware_acceleration status
    % Error: Unknown Parameter 'hardware_acceleration'

  • For a old P4 your system is performing quite well with 400Mb/s in my eyes. Most likely there isn't too much to tweak under the hood here. HW acceleration isn't available due missing AES-NI / Intel Quick Assist support in the P4.

     

    You might check the number of started IPS (snort) instances, but I'd expect already 2 instances (and your P4 to be a dual core with or without HT). So I personally would'nt expect too much more throughput for that hardware by further fiddling around in the base settings.

     

    /Sascha