Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Delay in loading first web page only

Hi everyone, I'm a long time UTM user that just made the cut over to Sophos Firewall and I've got one nagging issue that I can't figure out.  The first time a user goes to browse a web page, there is a delay of 10-15 seconds or so.  Once you get past that initial delay, all surfing is normal and will remain normal until there is a period of inactivity, which starts the cycle again. 

This issue also appears to only impact web browsing (or maybe all traffic on 80/443) but does not impact other traffic like ping.  Ping resolves a host name immediately without delay, even while I sit waiting for that first page to load.

I've got a basic setup at the moment with virtually everything at the defaults.  I've configured to Sophos to use 8.8.8.8 for DNS and I'm assigning that out with DHCP to clients.  No IDS/IPS, Web Proxy, or anything else is even enabled yet.

Here's the piece that I find really strange...

This delay only happens when a client has obtained their address through DHCP.  If I configure that same client statically, but using all the same info (IP, Subnet, Gateway, DNS) then the delay is gone.

For example, my main desktop has a DHCP reservation to assign it 192.168.210.100, subnet mask 255.255.255.0, gateway 192.168.210.1 and DNS 192.168.210.1.

When I use those same values but set the IP static instead of DHCP, no more delay in loading that first page.

I'm obviously missing something but I'm at a loss for what.  I just migrated off UTM 9.7x and did not have this issue.

Thoughts?



This thread was automatically locked due to age.
  • SFOS does not have the Proxy File placeable so it will not react to any requests. 

    UTM has a store of this file. So it likely will react and properly deny the client, leading to a direct result. 

    I never heard of an issue of clients running into a timeout by looking up this, which are caused by SFOS. 

    You could dump the client traffic with wireshark and check this. 

    __________________________________________________________________________________________________________________

  • Thanks, this is the best answer yet.  It doesn't solve the issue but it does provide a reasonable explanation for why it's happening.  I'll see what wireshark and some more tweaking will bring.

Share Feedback
×

Submitted a Tech Support Case lately from the Support Portal?