Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Poor IPSec VPN Throughput in One Direction

I have a site to site IPSec VPN tunnel between two Sophos XG firewalls.  They had been fine, but recently throughput has become an issue.

Both sides have symmetrical 1Gb circuits.  When testing with iPerf I am getting 250 Mb/s in one direction, but less than 3 Mb/s in the other direction.  I am not sure what has changed to cause this performance issue.

Neither firewall shows any significant CPU load or other significant activity.  The firewall rule is currently set to Log only between the two subnets.



This thread was automatically locked due to age.
Parents
  • Hi,

    please heck you ips settings in the gui. What version of XG are you running?

    ian

    XG115W - v19.5.1 mr-1 - Home

    If a post solves your question please use the 'Verify Answer' button.

  • I am currently running 18.5.2 MR2.  I just upgraded them a couple of days ago from the previous version to see if it would help with the performance issue.

    This is what I have in the IPS Policies section:

    However, the firewall rules in use for traffic across the VPN on these subnets only have logging enabled.  There is not an IPS policy applied to the firewall rule.

Reply
  • I am currently running 18.5.2 MR2.  I just upgraded them a couple of days ago from the previous version to see if it would help with the performance issue.

    This is what I have in the IPS Policies section:

    However, the firewall rules in use for traffic across the VPN on these subnets only have logging enabled.  There is not an IPS policy applied to the firewall rule.

Children
Share Feedback
×

Submitted a Tech Support Case lately from the Support Portal?