This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Slow internet using SOPHOS XG115w (SFOS 17.5.0 GA)

Before we were not using SOPHOS, the internet was not passing through SOPHOS and it was very faster.

But after install SOPHOS now internet is too much slow. So i don't know what is the issue..?

And if i tried to Disconnect SOPHOS and use direct internet its becoming faster again...!

Please i just need your help, if any one knows the solution,will appreciate..!



This thread was automatically locked due to age.
Parents
  • I have Shaw Cable Internet 600mpbs down 20mpbs up.

     

    For my appliance, I use a Dell Optiplex 7010, i5 Core with 8 GB RAM and 250GB SSD, with 2 x 1 GBps NICs (1 onboard and 1 PCIE).  Plenty of horse power for a firewall for home use with Enterprise qualities. 

     

    I downloaded and installed the SFOS 17.5.3 MR-3

     

    I had similar issue with the symptom where my Internet online speed went from 600 mbps down to a terrible 50 mbps.  I've rebooted the Sophos XG firewall and no go.  So I started to troubleshoot.

     

    Here are the settings that I have found I know WORKS:

    1.) Network > WAN > Advanced > Interface Speed, I had to change mine from 100 Mbps Half to 1000 Mbps Full

    2.) Firewall > firewall rule (#default)

    - enable Scan HTTP 

    - Traffic Shaping = High Guarantee Rule

    - Web Policy = Family Web Policies (custom web content filtering policy)

    - Application Control = Allow All

     

    Notice I skipped Intrusion Prevention?  After much tinkering and troubleshooting, I found that IPS is the CAUSE of the problem.

    Set the IPS to WAN TO LAN is better and makes logical sense...because you are protecting your internal network from the outside.  Does not make sense to choose LAN TO WAN policy.  

    When IPS is enabled initially, it is okay.. but after a day or two, my Internet speed went from 600 to 50.  Again.  Rebooting the firewall did not resolve the issue.  I had to set the IPS to none, then save, and the speed was back to normal.  Something is definitely wrong with the IPS.  

    Either keep recycling that IPS setting on a daily base...which is stupid, OR, disable it completely... which is stupid as well... I mean, IPS is there to block intrusion attempts.  Right?  What a pickle this is.

     

    Also, what I found can cause the problem, if you had specified Traffic Shaping on the Default rule, do not specify that same traffic shaping rule on the other fw rule, that will really slow it down which I found out.

  • Hi,

    your logic is sound, but wrong, you need to be using the LAN to WAN IPS.

    You will need to tun e the PS DOS settings

    What the large values in the detected column are i don't know because I have been playing with a number of applications that are not network friendly.

    I have also changed the values in some of the protocols.

    Since I took that screen shot I have disabled the destinations except for the icmp/6 fields.

    Ian

  • Hello Ian,

     

    I chose WAN TO LAN because the description describes my scenario for my virtual lab.  LAN TO WAN are for lan-based clients which are not applicable to me for my lab.

     

Reply Children