This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

SFOS 18.0.3 MR-3 - DPI performance

Hi,

I have tested a while with DPI engine, but I am a little lost with the perforamance tuning.

With everything off I get 420Mbit

When I enable DPI SSL/TLS inspection with decrypt, IPS Policy LAN TO WAN I can only get 170MBit through.

I have enabled:

console> system firewall-acceleration enable
Firewall Acceleration Enabled Successfully.
console> system firewall-acceleration show
Firewall Acceleration is Enabled.

Any hints on what I made wrong? :-)



This thread was automatically locked due to age.
Parents Reply Children
  • Thanks for this, I guess it working because of this:

    Firefox version 52: Firefox will also search the registry locations HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Root\Certificates and HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root\Certificates (corresponding to the API flags CERT_SYSTEM_STORE_LOCAL_MACHINE_GROUP_POLICY and CERT_SYSTEM_STORE_LOCAL_MACHINE_ENTERPRISE, respectively).

    But why FF is was faster to do http speed test?! Odd...

    -----

    Best regards
    Martin

    Sophos XGS 2100 @ Home | Sophos v19 Architect

  • Ahh found out something:

    FF: https://xn--bredbnd-ixa.dk/hastighedstest 420Mbit

    EDGE: https://xn--bredbnd-ixa.dk/hastighedstest 170Mbit

    -----

    FF: https://www.speedtest.net/ 420Mbit

    EDGE: https://www.speedtest.net/ 420Mbit

    Guess with DPI it's the best thing to do plain iPerf testing from now on :-O

    -----

    Best regards
    Martin

    Sophos XGS 2100 @ Home | Sophos v19 Architect

  • It's been a few years since I had to do any throughput troubleshooting but I do remember that speedtest.net tests using multiple threads which is not very helpful for troubleshooting this sort of issue as it hides performance issues. If, for example, it uses 6 threads then each thread only has to achieve 70Mbit for you to think you are getting your full 420Mbit overall. You really need to use a test that works with a single thread like iPerf can. There are speedtest websites that offer single thread tests but I can't remember the one I used.

    Update: While looking for a single thread website test I found that speedtest.net does offer this as an option but I couldn't find it on its website. You may have to create an account to be able to set that preference.

  • Thanks, makes perfectly sense :-)

    -----

    Best regards
    Martin

    Sophos XGS 2100 @ Home | Sophos v19 Architect