Hi,
sorry for the long read.
Short version: WAN connection breaks down after 10 minutes in a KVM/proxmox virtualized Sophos XG instance.
Verbose mode:
I've been using Sophos XG for some days now, and i'ts really a cool piece of software. Goal is to have control over youtube and other services (my kids are becoming addicts...), which was achieved pretty easily :)
My setup is a proxmox host (6 core xeon, 64gb ram, some ssds, some hdds, a dvbs-tuner, 2 onboard nics and a twoport pcie 82571EB nic).
Sophos is running with 8GB ram, 4 processors, the twoport 82571EB attached via pcie passthrough. Runs very nicely, download speeds around 70-80mbps with my 1gbps cable connection, everything perfect.
Except, after a while of heavy downloading (~20GB, or 10 Minutes), internet connectivity starts to break down slowley: After 10 Minutes one first ping timeout... 3 minutes later the next one... 1 minute later another one.. then after 30 secondes, after 15, after 5, after 3, then everything goes down until i cancel the download. It really looks like something is running full or hot and then stays full / hot.
In the shell everything looks easy, cpu is at 3-5% disks are spacey, no uncommon log messages.
The web frontend is reacting normal. But as soon as i start to download anything bigger then a website now, the wan connection breaks down immediatley.
Whats specificly odd: When i click on Network->Edit WAN Port->Save ("All connections will be dropped -> OK"), everything starts working again (for the next round of 10 Minutes / 20GB)
I've already set up a fresh sophos-instance, and the problem started immediately after the first ready boot. To rule out network problems, I've also switched back to my providers router, everything running nice and stable there.
What i've also tried so far without any effect is this:
ethtool -K Port1 rx off tx off tso off gso off gro off
ethtool -K Port2 rx off tx off tso off gso off gro off
(I really dont have much of an idea what i did there to be honest):
system firewall-acceleration disable
Replacing the network adapter with a different (4-port) Intel pcie-card.
I don't know how to proceed any further, not even where to look...
Thanks and best regards,
Tobias
This thread was automatically locked due to age.