This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

SFOS 18.0.3 MR-3 - DPI performance

Hi,

I have tested a while with DPI engine, but I am a little lost with the perforamance tuning.

With everything off I get 420Mbit

When I enable DPI SSL/TLS inspection with decrypt, IPS Policy LAN TO WAN I can only get 170MBit through.

I have enabled:

console> system firewall-acceleration enable
Firewall Acceleration Enabled Successfully.
console> system firewall-acceleration show
Firewall Acceleration is Enabled.

Any hints on what I made wrong? :-)



This thread was automatically locked due to age.

Top Replies

  • I have not uploaded Appliance cert info firefox.

    Firefox doesn't use your system CA store, It has It's own; Since you didn't upload the certificate into Firefox and didn't got any warnings while browsing, It means It is using the Web Proxy without HTTPS Decrypt - hence if It has using DPI and you have the TLS Inspection rules in place, Firefox would give a warning saying that the firewall certificate is not trust-able.

    Edge In-private 176Mbit

    Firefox Private 413Mbit (Ful speed of ISP)

    It's hard to measure firewall throughput through HTTP speed-tests. But It shouldn't be that slow for the SG 210 Rev. 3.

    Also, can you take a picture of the CPU usage with "top -d 1" command on the shell while doing a speed test ?

    Jump to answer
Parents
  • I can also confirm that dpi has some affect while browsing web. According to previous version of XG. There is no speed performance cuz if im doing speed test then 1gbs is reachable. But overall loading  website. I did some testing amd without dpi it works like a charm. Also SSLVPN via UDP performance still sucks :(

    __________SETUP___________

    HP Small Form Factor:  i5 4Cores, 8Gb of RAM.
    Intel Network Card 5x Eth
    SSD: 256Gb

Reply
  • I can also confirm that dpi has some affect while browsing web. According to previous version of XG. There is no speed performance cuz if im doing speed test then 1gbs is reachable. But overall loading  website. I did some testing amd without dpi it works like a charm. Also SSLVPN via UDP performance still sucks :(

    __________SETUP___________

    HP Small Form Factor:  i5 4Cores, 8Gb of RAM.
    Intel Network Card 5x Eth
    SSD: 256Gb

Children
No Data