Guest User!

You are not Sophos Staff.

Parents
  • PS: Try the new DPI Engine Performance. 

  • Hi,

    currently using DPI for my various access in IP4 and IPv6 rules. The devices I have tested so far are my wife's MAC Air MI running latest firefox and accessing facebook, no apparent issues with my general testing.

    Ipad using FB app and other activities all works vey well.

    MAC Mini intel - appears to have fixed a lot of failing connection issues part the way through downloads from a photo album site and the downloads are very quick eg faster than I can scroll down to see if any entries have failed. Waiting for TOR browser to connect or fail. It has been trying for about 10 minutes so far - should be blocked.

    Question, has the new DPI engine been fixed to work with mail scanning, I will test myself later.

    Tomorrow's and the following days reports will be interesting to see what the date fix has done to the reported data.

    Ian

    There is a tradeoff with using the DPI engine in that you still need web proxy to achieve web site blocking as per the warning when you disable http proxy.



    added comment about still needing web proxy to block some websites.
    [edited by: rfcat_vk at 10:28 AM (GMT -7) on 15 Jul 2021]
  • What a good update!

    I've enabled back again "security.tls.enable_delegated_credentials", and Firefox is working flawless with Facebook now. (With TLS Decryption.)

    Another thing I noticed, there is much less random TLS errors with Firefox now.

    Thanks!

  • What about the Performance? Can you reflect some improvements? 

  • I'm a Home User, but doing some generic (flawed) testing the most noticeable thing is TPS, currently It's much faster than v18.0.

    While doing TLS Decryption over a local Nginx server using TLS 1.3 and AES256GCM-SHA384, on a 1 Byte file, the TLS transaction per second went from ~13.200 to around ~18.600. But there's no difference on raw decryption throughput from v18.0.

    Also, the Decryption Limit got lowered on my box, I don't know why; It went from 18.4K to 12.3K.

    For Internet traffic It just "feels faster". (I've didn't looked a lot on this.)

  • The max session is based on RAM available on the Appliance. 

Reply Children