This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Slow first response HTTP / HTTPS

Hi,

i am trying to troubleshoot an issue with a XG Firewall SG115 running SFOS 17.5.6 MR-6.

1. When I open a http website e.g. http://google.de the request will be redirected to https://www.google.de and first response is slow when "http scan" in firewall rule is enabled. When open https://www.google.de directly, response time is good.

2. When I set a policy at intrusion prevention inside the firewall rule, both http and https first response is slow, regardless of "http scan" enabled or disabled.

3. When I set sophos as a fixed proxy in the browser the response times are fine.

What could be wrong ? Is this standard behaviour or eventually some configuration mistake ?

 

Thanks in advance for all help.

 

Regards,

Thomas



This thread was automatically locked due to age.
Parents Reply Children
  • The correct way when you have a server with dns server (domain controller) is the way the he configured.

    The server has to have himself as the dns server, and in the dns server properties, you have forwarders, there he can configure any external dns server he wants. the fastest should be your ISP, but sometimes 1.1.1.1 is better. All workstations should have the local DC dns as their dns server.

    The firewall wan should have the same as the forwarders in the Servers DNS. can be the ISP or the 1.1.1.1

    For test case, when you feel it is slow in the first site I always ignore my recommendations and manually configure the workstation and the firewall wan with external DNS server. Just for testing to get the fastest DNS.