Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Site to Site Connection Slow on XGS116 and XGS2300 with big Files

Hi there,

I have a site to site Connection from a Site A XGS116 1GB/300MBit to a Site B XGS2300 1GB/1GB.

First i use encryption IKEv2. With this Configuration it was not possible to work with the Shares.

Click on a File with about 300 MB, a blue Circle appears and nothing happens. (IPS deactivated) 

After hours of research, i found out, that if i lower the encryption to unsecure MD5, working is possible.

When i download a File, its downloading constantly with 15MB/s. Before a Download was not possible, Speed began with 15MB/s and lower down to 0.

Now MD5 is unsecure. 

Going back to IKEv2 and turning off the IPSec Accelaration and i have 15MB/s back. So far so good. How can i speed up this site to site?

The MTU is now 1500. If i make a ping to Site A from the Server, i get a Packet fragmented. If i ping with Ping 192.168.40.254 -f -l 1378 i get an answer.

Do you think it will speed up the Connection if i lower the MTU on both Sites to 1378 or has anyone another clue?

Sophos Support says my Hardware is to low, but it is only 1 Site to Site in both firewalls, i cannot believe this.

Thanks for your help

Markus



This thread was automatically locked due to age.
Parents
  • Hello Markus,

    Greetings!

    If you have captured the tcpdump on destination IP address, while file transfer and if you have observed that server replied with the lower MSS. Certainly, lowering down the MTU/MSS of the LAN interface would help! You will need to lower down the MTU and MSS of the interface for which the network used in IPSec! 

Reply
  • Hello Markus,

    Greetings!

    If you have captured the tcpdump on destination IP address, while file transfer and if you have observed that server replied with the lower MSS. Certainly, lowering down the MTU/MSS of the LAN interface would help! You will need to lower down the MTU and MSS of the interface for which the network used in IPSec! 

Children