Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Site-to-Site IPsec Tunnel, Poor Performance

Hi I recently migrated from the UTM series to the new XGS 3300 line. I currently have re-established a site-to-site tunnel between my branch and head office sites. I am experiencing very poor VPN tunnel speeds. My head office has a 2.5Gb fibre connection while my branch office has a 100Mb connection. 

I was getting very decent connection speeds back on the UTM series, however now with the migration of both sides have started to experience slow speeds. Initially I had left everything as default, so IPsec tunnel acceleration was enabled by default, which appeared to work and transfer speeds were great. However on large transfers it appears to stall half way and go from seconds to hours of transfer times. After I disabled IPsec tunnel acceleration, my throughput between sites was drastically reduced and I have not gotten above ~1MB/s transfer speeds (or ~8Mbps), however large files were now transferring fully. 

Both sides have the same settings for IPsec profile:

IKEv2

Phase 1

  • Key Life: 28800
  • Re-Key: 540
  • DH Group: 15
  • Encrypt: AES256
  • Auth: SHA2 256

Phase 2

  • PFS Group: Same as Phase 1
  • Key Life: 6000
  • Encrypt: AES 256
  • Auth: SHA2 512

What can I adjust or look at to improve this performance? 



This thread was automatically locked due to age.
Parents
  • Hello there,

    Thank you for contacting the Sophos Community.

    Try disabling IPsec acceleration, you can do this by accessing to the console of the XG, using Putty, after entering your credentials, press 5>4 and then type:

    console> system ipsec-acceleration show
    IPsec acceleration status: turned on

    console> system ipsec-acceleration disable

    This will restart all IPsec tunnels and stop offloading IPsec VPN traffic to the Xstream flow processor.

    Turn off IPsec acceleration(Y/N)?
    Y

    Regards,


     
    Emmanuel (EmmoSophos)
    Technical Team Lead, Global Community Support
    Sophos Support VideosProduct Documentation  |  @SophosSupport  | Sign up for SMS Alerts
    If a post solves your question use the 'Verify Answer' link.
  • And try to disable the firewall acceleration as well. See if it impacts your performance or not. 

    __________________________________________________________________________________________________________________

Reply Children