Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Packet loss when not using VPN XGS87w

Hello,

I have an odd issue with an XGS87w recently installed. We experience a lot of packet loss when using the device's WAN connection to external addresses and the reverse. The packet loss clears up for about two minutes every 20 minutes or so. The loss is also not present when using SSL VPN to connect to device. I may be missing something obvious here but the device has very basic config with allow all out firewall setup and a few VPN users. I'm not really sure how to troubleshoot this issue. We have contacted the ISP regarding the loss and they saw some signal data out of spec but then why does the VPN clear up the packet loss? Any advice is much appreciated.

Image 1 is from device during issue - There is one incoming and one consumed entry for every outgoing, I assume this is the same packet and that device is reporting that it is responding to every echo request.

Second image is from laptop during test where we see only one response packet arrive for every request.

Ping from external address to WAN address - ~50% packet loss most of the time

Ping from device to external address - ~50% packet loss most of the time

Connect from external site to VPN and ping LAN over VPN - No packet loss



This thread was automatically locked due to age.
  • FormerMember
    0 FormerMember

    Hi ,

    Thank you for reaching out to Sophos Community.

    Did you observe the issue only with ICMP traffic or with web traffic as well?

    Could you please take an observation by disabling firewall acceleration?

    ==> Login to SSH > 4. Device Console

    console> system firewall-acceleration disable

  • I was able to test some more today.

    The issue presents itself with all traffic types. Disabling the firewall-acceleration had no change. I had not mentioned it previously but this firewall was a replacement for an XG model and the config was imported. There were no errors and the Sophos support site has this listed as a support config backup/import scenario.

  • This issue was resolved when on site via factory reset and configuring system from scratch and not importing the backup from the previous device. Still not sure what the root cause was.