Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

XG v18 MR4 - Massive performance issues with Sophos VPN connections

Hello Sophos Community,

I am trying to nail down a massive performance issue that prevents us from copying greater files between headoffice and branchoffice over site-to-site vpn tunnels.

Referencing the following thread, this pretty much describes my issue since the problem does not only appear with IPsec VPN Tunnels but also with Client SSL VPN exactly the same pattern and tiny throughput regardless of the used internet connection:

https://community.sophos.com/sophos-xg-firewall/f/discussions/101100/ssl-vpn-connection-slow-warning-large-screenshots

I am running all appliances with v18 MR4. In the thread a fix was mentioned with MR2 but this does not seem to apply for me (or the issue returned with MR4)

The underlying network infrastructure has 200 Mbit/s throughput as weakest part of the chain (ISPs up and download, internal cabeling, storage, etc)

The vpn tunnel was build between XG 750 and XG 135. SSL VPN Clients connect directly to XG 750 so it is not related with XG 135 hardware.

Multiple branchoffices are affected.

Additional information about client vpn cryptographic settings:

and the used ipsec policy for site-to-site tunnels:

There must be some bug or missconfiguration that leads to such a crazy bottleneck. Anyone else experiencing issues with very low bandwidth over Sophos VPNs and has some hints for me?

I appreciate your feedback.

Kind regards,

David



This thread was automatically locked due to age.
  • FormerMember
    0 FormerMember

    Hi ,

    Thank you for reaching out to Sophos Community.

    Can you please take an observation of total Rx & Tx packets on ipsec0 virtual interface while copying data from either side?

    # iftop -i ipsec0

    Please check throughput by disabling DoS(SYN/UDP flood).

    Could you also please take an observation with a Route-based VPN?

    Click here to know more information on RBVPN(Route-based VPN).

    TechVidshttps://soph.so/yk7BUH

  • Thank you for the diagnostic command, I was not aware of this feature until now. Funny thing is, that I am unable to reproduce the performance issues today. It needs to be some sort of traffic peak that shows every now and then in our network since the issue persists "sometimes" for a while allready. Maybe I am able to find additional answers the next time it appears with the command above.

    I will report back then.

    Thanks and enjoy your day!