Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

4000 mbps LAG on a XG 125 v3 help

What I have setup is on a 125 running XG 19.0 .  I have these interfaces:

eth0 LAN which shows 1000 mbps- full deplex/ connected

LANLAG/ LAG1 with 4 ports (eth2/3/4/5) in LACP mode on the LAN network zone.  and it shows up in GUI as 4000 mbps full deplex/ connected.  I also created vlan40 (VLAN-lag) for this interface.

In zone- LAN I have 

LANLAG, VLAN-LAG, eth0, eth2, eth3, eth4, ehth5

All 5 of these ports go to a 48 port edgemax switch.  I put eth2/3/4/5 in a LAG1 group on the switch P-39/41/43/45 and not eth0 (port 37).  In the switch I have it set as LACP/ load balance mode - "Source/ destination MAC, VLAN, Ethertype, incomming port".  In the switch I have all 5 ports trunked, Untagged in the default network, and tagged in every network that I have.  I also have vlan41, and 42 in the switch with LAG1 only..   #Show lacp partner = this and the 4 ports have the same MAC

 

Show port-channel brief

The issue that I have is that this causes about a 10% drop on which ever port in the LAG1 (on switch) is moving the traffic.  All 4 ports in this lag (switch) show 1G full duplex.  1 might jump to 800mbps and the other 3 will have a few kbps, I can disable the port moving traffic and the traffic will pop up in the another port.   I can disable all 4 and the port 37 (attached to eth0) will take over.  In the sophos without the lag group I get 0 drops.     Should I have port 37 in the LAG1 group?    If my switch is using LACP shouldn't I see a 4G interface somewhere and shouldn't my ports in the group show the same RX and TX as the other ports?   LAG 2 does the same which is connected to a synology NAS which inside the the control center/ network says bond 1= LAN1,2,3,4 and shows 4000mbps full duplex.   I get no drops on LAG2 but the ports in the switch GUI are never equal like 40/40/40/40.



This thread was automatically locked due to age.
Parents Reply
  • Hi Charles, for the best load balancing on LAG interfaces, you need to set it as high as both sides can.

    So, The XG does Source/Destination hashing regardless of the layer.

    Layer 2: mac/port

    Layer 3: IP protocol

    Layer 4: tcp/udp port.

    So best results and actual load balancing between two endpoints is with Layer 3 + Layer 4.

    On your switch this is the bottom option.

    P.s. do not switch to static interface speed settings, leave it on auto, also change MTU back to default 1500, any other will bring big problems if you do not know what your doing.

    Bart van der Horst


    Sophos XG v18(.5) / v19 Certified Architect
    https://www.bpaz.nl

Children
  • An other question, why do you want a LAG interface with 4 connections? The XG125 is nowhere capable of doing 4000 Mbit firewalling.

    Bart van der Horst


    Sophos XG v18(.5) / v19 Certified Architect
    https://www.bpaz.nl

  • What i s the limitation of the XG125?  I Thought the LAN throughput is 6.5 Gbps.  

    I have 1G fiber WAN, then I have several local severs on 10G SFP and 2 servers on synology rack mounted servers that have 4 channels bonded. Then I have several PC's that have 10G cards in them. I have a 5 switches that have 10G links to each other. All of the devices show 4 or 10 Gbsp.  From my understanding I cant move or anything from 1 server to another at anything near these speeds without creating a lanlag group within my sophos? 

  • I also made the following adjustments in the Sophos.. Changed the MTU back to 1500 and the Xmit hash policy to Layer 3+4 in the LANLAG Group

    In the switches,... I made all of the LAG groups load balancing =  IP and TCP./UPD

    Now it appears that the ports do have a data moving across all 4 at the same time, So it appear that the LAG group is working.   I also  reset the drop/error counters and I am still getting drops on those 4 ports.  So Looks like I had 2 issues and I have one fixed.

  • Could be the cable / port broken? 

    __________________________________________________________________________________________________________________

Share Feedback
×

Submitted a Tech Support Case lately from the Support Portal?