Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

SSL VPN SLOW

Dear all,

We are having a XG310 sophos appliance with Version 18.04 MR-4 & SSL configuration enabled. Here we are having 70Mbps BSNL, 40Mbps TATA, 10Mbps JIO and 100Mbps ACT Broadband line @ WAN side.

There are 300+ users are connecting to it from thin clients at remote end through openvpn.

We are facing very slow Remote Desktop connection from the client end and we suspect that all the SSL traffic is passing through only 10Mbps JIO line and the BSNL 70Mbps line is not utilized.

We need to know the behavior of SSL traffic and is there any possibility to assign or route all SSL vpn traffic to BSNL 70Mbps WAN?

Thanks in advance,

Stephen.J



This thread was automatically locked due to age.
Parents
  • FormerMember
    0 FormerMember

    Hi ,

    Thank you for reaching out to Sophos Community.

    SSL VPN user configuration file has information of all active WAN interface IP addresses.

    When you connect SSL VPN client, it initiates SSL connection request to each IP address in the round-robin method and connects with an IP address that responds to the SSL request.

    To connect SSL VPN to a specific IP, you can configure override hostname in SSL VPN settings or can also configure proxy on SSL VPN client.

    SSL VPN settings:

    SSL VPN client settings:

    Changing override hostname in SSL VPN settings will lead the user to reinstall the SSL VPN configuration file.

  • Dear Yash,

    Thanks for the reply and we are having another complication that we are using ncomputing RX300 thin client for the remote users. Here, we can't reinstall the config file as all the devices are in their USER'S residence.

    We couldn't bring back all the devices to our office for config file installation and kindly suggest us that there is any other option to route the SSL vpn traffic?

    Thanks in advance,

    Stephen.J

Reply
  • Dear Yash,

    Thanks for the reply and we are having another complication that we are using ncomputing RX300 thin client for the remote users. Here, we can't reinstall the config file as all the devices are in their USER'S residence.

    We couldn't bring back all the devices to our office for config file installation and kindly suggest us that there is any other option to route the SSL vpn traffic?

    Thanks in advance,

    Stephen.J

Children