Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

IPSEC vpn slowness in one direction between sites using XG Firewall at each.

Site A: 300mbps up/down
Site B: 1gbps up/down
Both are Sophos XG Firewalls and are connected over WAN using an IPSEC VPN Tunnel
Observations:
Site A to Site B file transfer
utilization of about 250mbps (Great! the tunnel is clearly using most of the bandwidth from the slowest site)
Site B to Site A file transfer
SLOW transfers of at most around 30mbps
I can check WAN saturation on each side and not seeing any indication there is saturation happening.
Site A and Site B can both get to the internet and speed tests indicate everything is working at the ISP speed we pay for.
Has anyone else seen this happening or can give some insight on some things I can test or look for to help remedy this slowness? Thanks!
 


This thread was automatically locked due to age.
Parents
  • FormerMember
    0 FormerMember

    Hi ,

    Thank you for reaching out to Sophos Community.

    Are there any restriction policies(web/app/ips/qos) applied on LAN to VPN firewall rule at SiteB?

    Do you have DoS enabled on the firewall?

    At the time of file transfer, check the total utilization(Rx & Tx packets) for IPSec using the below command.

    Login to SSH > 5. Device Management > 3. Advanced Shell

    # iftop -i ipsec0

    Also, check the utilization of WAN interface at that time.

Reply
  • FormerMember
    0 FormerMember

    Hi ,

    Thank you for reaching out to Sophos Community.

    Are there any restriction policies(web/app/ips/qos) applied on LAN to VPN firewall rule at SiteB?

    Do you have DoS enabled on the firewall?

    At the time of file transfer, check the total utilization(Rx & Tx packets) for IPSec using the below command.

    Login to SSH > 5. Device Management > 3. Advanced Shell

    # iftop -i ipsec0

    Also, check the utilization of WAN interface at that time.

Children
No Data