Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

New XG125 w/ V4 Firmware

SOPHOS ISSUES   XG125 New Oct 2020

1) Extremely and I mean EXTREMELY slow admin interface.   Approx 15-30 seconds each and every time you make a change to any parameters before it is completed writing it, and refreshing the screen.   You need to plan carefully because if you have a dozen or more rules to add, it takes quite a long while to enter.

2) Screen does not allow enough space to see the name of the Address object it cuts off after 3rd segment, ie.  192.168.100.    so you must mouse over each and every rule to find the right rule.   Very time consuming and needless.   Allow full width of the screen and the problem is solved.

3)  WIth 21 rules added and associated NATs entered, the XG is showing 78% memory usage.  What??   Why, I haven't entered any VLAN information yet.  What happens when it is 90,95 or more % filled does it just keel over?

4) It takes MINUTES to reboot, plan carefully because you will be offline for at least 5-6 minutes.

5) Right out of the box, could not configure 100/FULL Duplex, could not get WAN Link light.   Had to configure it 1GBe/FULL and pay the extra at the hosing facility. OK perhaps that is fine, but WHY?

6) VPN,  Cannot select from multiple VPN END POINT .   Meaning, if you have more than one location, you must rename the configuration file and use the configuration file specific the the End point you want to connect to.   Someone really has to be kidding with this one, it is not 1971 is it?

7) High CPU usage 50,65,80% CPU and the unit is not even active yet.  WHY?   It settles down after while to 10,20% but what is it doing during the other moments.   Again no traffic yet.

8) Some NAT Rules seem to go offline after 15-20 minutes and need to be resaved and take effect again for 15-20 minutes.   Not all of them, just some of them.  What?  Again how could that even be possible and really raises concerns about this particular device quality.   Regardless paying extra to have the authorized reseller research the issue but can't turn this on this way.

POSITIVES

     Country blocking interface is easy to configure and worked reasonably well.   But not certain the SOPHOS Country IP list is really up t date, because it is letting through some that are "Blocked" zones.

     Cost, it was cheaper than all of the other manufacturers at similar hardware levels by 30%.   Got me to buy it, but see issues...is it worth the extra trouble?

     Some reporting seems better than others like Sonicwall, CISCO ASA (who's reporting is really quite inadequate by default), but Sonicwalls don't have the other 8 problems above and we have had a dozen of them of all sizes.

     Colors on the graphs are nice, but what pertinent information am I getting with those graphs?

Lastly, all of this having been said.   There might be corrections available for #5, #6, #8.   But the others seem like something we would have to just live with...not sure that is reasonable to and very uncomfortable putting any load on this with CPU and Memory where it seems to be.   We have a SG125 also that we loaded the XG software onto as well...same thing (except #8 not happening).



This thread was automatically locked due to age.
Parents
  • Hi Robert,

    1) This is not the fastest but not that slow. Don't have a XG 125 but Interface speed is not muxh correlated to the price of the device(which means that on a XG 550 is also not the fastest GUI on earth and not much faster than a XG 135). I assume it is single threaded an depends on the speed of one processor.

    2) Yes search options and references should be a must in "Enterprise" level. Organize by groups in source and destination zones. This helped me. Everything is very space consuming and you need to scroll a lot.

    3),7) Check what processes are consuming CPU and memory (CLI+Top). We had some testing packets with random destination addresses that hit the firewall at a rather low bandwidth. This was driving the IPS mad and after disabling it on the affected rules everything ran much smother (could be another issue in your case - e.g. you are attacked heavily and the IPS is getting mad on the WAN side). 

    4) Not to unusual for every pc hardware. If you need HA or better availibility consider to make an active-passive cluster. You only have to pay hardware maintenance + hardware of the second firewall. This also reduces the downtime at updates for most services to 0 (some services are not clustered - especially VPN Stuff).

    5) This is under Network - Interfaces - Advanced Setting (could not test - everything on 1 GBit/s)

    8) Have never seen this.

    (Using XG 550, XG 210, XG 135W)

Reply
  • Hi Robert,

    1) This is not the fastest but not that slow. Don't have a XG 125 but Interface speed is not muxh correlated to the price of the device(which means that on a XG 550 is also not the fastest GUI on earth and not much faster than a XG 135). I assume it is single threaded an depends on the speed of one processor.

    2) Yes search options and references should be a must in "Enterprise" level. Organize by groups in source and destination zones. This helped me. Everything is very space consuming and you need to scroll a lot.

    3),7) Check what processes are consuming CPU and memory (CLI+Top). We had some testing packets with random destination addresses that hit the firewall at a rather low bandwidth. This was driving the IPS mad and after disabling it on the affected rules everything ran much smother (could be another issue in your case - e.g. you are attacked heavily and the IPS is getting mad on the WAN side). 

    4) Not to unusual for every pc hardware. If you need HA or better availibility consider to make an active-passive cluster. You only have to pay hardware maintenance + hardware of the second firewall. This also reduces the downtime at updates for most services to 0 (some services are not clustered - especially VPN Stuff).

    5) This is under Network - Interfaces - Advanced Setting (could not test - everything on 1 GBit/s)

    8) Have never seen this.

    (Using XG 550, XG 210, XG 135W)

Children
No Data