Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Sophos XG 125 v18 - How to monitor and troubleshoot performance? Tuning tips

Hi Guys,

I have XG125 rev.1 I beleive with 30/30 WAN connection. Basic setup with a few VLANs, some IPSEC tunnels, web filtering etc. nothing fancy here :-)

But remote users are complaining about occasional performance issues of RDP, or some other services via SSL VPN into our LAN. I even get some VPN disconnections. Or some internal users also occasionally reports slow internet connection. SSL/TLS inspection is off.

If I check all the metrics, it seems quite OK to me...

CPU 20-60% with very rare spikes to 80%
RAM around 60% all the time
Bandwidth Max 3.93MB Avg 584KB (yes it peaks to maximum throughput)
Sessions Max 1053 Avg 249.09
Online VPN Users 25-40 during business hours

It seems to me, that our WAN is the issue and we need to upgrade our 30/30 connection as it won't handle the peak hours. But I want to be sure XG is handling the traffic fine.

Any tips for some more advanced diagnostics?
Do you think XG125 should be able to handle this kind of traffic just fine?
Any thoughts how to improve the setup? Like shape vpn throughput for a users or switch to IPSec VPN for the remote access etc?
Or some other tuning tips for better performance?

Thanks for any help on this!

Martin



This thread was automatically locked due to age.
  • Hello,

    But I want to be sure XG is handling the traffic fine.

    All appliances already come with the best performance tuning by default, there's not a lot you can do to get better throughput.

    There are two crucial issues, first is your WAN connection which is slow from 25-40 VPN Users; The second is SSLVPN which is heavily single threaded and much slower than IPsec VPN.

    My recommendation is to use Sophos Connect with IPsec for remote access if possible.

    Thanks!

  • Thanks! I'm already thinking of migrating a few users to IPSec and see if it helps.