Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Site to Site Connection Slow on XGS116 and XGS2300 with big Files

Hi there,

I have a site to site Connection from a Site A XGS116 1GB/300MBit to a Site B XGS2300 1GB/1GB.

First i use encryption IKEv2. With this Configuration it was not possible to work with the Shares.

Click on a File with about 300 MB, a blue Circle appears and nothing happens. (IPS deactivated) 

After hours of research, i found out, that if i lower the encryption to unsecure MD5, working is possible.

When i download a File, its downloading constantly with 15MB/s. Before a Download was not possible, Speed began with 15MB/s and lower down to 0.

Now MD5 is unsecure. 

Going back to IKEv2 and turning off the IPSec Accelaration and i have 15MB/s back. So far so good. How can i speed up this site to site?

The MTU is now 1500. If i make a ping to Site A from the Server, i get a Packet fragmented. If i ping with Ping 192.168.40.254 -f -l 1378 i get an answer.

Do you think it will speed up the Connection if i lower the MTU on both Sites to 1378 or has anyone another clue?

Sophos Support says my Hardware is to low, but it is only 1 Site to Site in both firewalls, i cannot believe this.

Thanks for your help

Markus



This thread was automatically locked due to age.
Parents Reply
  • What firmware version are you running on the firewall, Some other things to note down here, Please see if IPsec acceleration is enabled on both the appliances : 

    console> system ipsec-acceleration show 
    IPsec acceleration status: turned on

    Also AES 128 GCM ciphers are less CPU intensive than that off the AES 250 CBC they should yeild much better performance. Also is there a NAT involved in either side WAN interface having a private IP ? or are you terminating your tunnel on an alias interface ? if yes try it on the parent interface You can also change to IKEv1 

    is there a LAG in the picture on the WAN interface on either sides ? 

    -Cheers,

    Kranthi

Children