Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

XGS series: SSL/TLS inspection throughput improvement


In XGS series, SSL/TLS inspection throughput has increased significantly compared to XG series.

I guess the inspection is processed not by NPU (Xstream processor) but by CPU and I'm interested in how it was possible to achieve such a significant performance improvement.

75 Mbps in XG 86 -> 375 Mbps in XGS 87 (5X improvement)
230 Mbps in XG 210 -> 1,100 Mbps in XGS 2100 (4.8X improvement)

According to the brochures below, the test methodology might be different between XG and XGS.

Performance Test Methodology
XG series
https://www.sophos.com/en-us/medialibrary/pdfs/factsheets/sophos-xg-series-appliances-brna.pdf
Xstream SSL decryption: Measured with IPS and Threat Protection enabled using HTTP traffic with 192KB response size.

XGS series
https://www.sophos.com/en-us/medialibrary/pdfs/factsheets/sophos-firewall-br.pdf
TLS inspection: Performance measured with IPS with HTTPS sessions and different cipher suites

Your appropriate advice will be appreciated.



This thread was automatically locked due to age.
Parents Reply Children
  • Almost everything important can be offloaded on those Marvell Octeon NPU's. (Depending on the model.)

    But not even IPsec is being offloaded on It right now, apparently It will take some time until the real performance of those appliances shows off.

  • The point is, you can upgrade the firmware later and handover more traffic in the future. So Sophos is on the point, giving customers significant more performance with a firmware update, which is oddly, as most likely firmware upgrades in IT means decrease of performance. You can simply code the offloading into a firmware upgrade, no need to upgrade the hardware.