Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

TCP Retransmissions, Reset and Dup packets through IPSec tunnel , Slow access thorugh tunnel

Hi Guys, 

This is after 2 months of troubleshooting, escalations, helplessness from Sophos support, i'm writing this. I have this issue since we deployed the new XGS 4500 firewalls and still not able to resolve this. One of our core application is hosted in AWS and we need to access it from LAN. 

Literally all of my Developers sitting in office are connecting to their mobile hotspots to get their work done, leaving the 1Gig leased line. 

So here is the issue. 

1. User sitting in office and connect to Application in AWS - continuous transmissions, RSTs, Dup Acks 

2. Same user connects to mobile hotspot, connects to SSL VPN, and then accesses the same application through same S2S tunnel, Works fine. 

3. Users sitting in different state connects to VPN and tries to access the same application - again works fine. 

4. Same user sitting LAN and connecting to SSL VPN to the same public IP of the firewall - again the application works fine. 

So basically, when users are in LAN Zone and connecting to the application are seeing severe delay, latency in accessing the application. 

None of the other applications, internet is impacted, all works perfect from LAN. 

This is driving me nuts, please help. 

Sampath



This thread was automatically locked due to age.
Parents Reply
  • Could be potentially something like a MTU issue. 

    Within your network you likely use MTU Sizes of 1500.

    SSLVPN uses 1400 MTU Size. So if the client sends the packet with MTU of 1400, it could actually resolve this.

    Try to reduce the MTU of your Client on LAN to 1400 and see, if the issue resolve itself in LAN. Then going forward you could potentially investigate the Application, if there is something like DF (Dont Fragment) Pakets be used. 

    __________________________________________________________________________________________________________________

Children