Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

LAN to WAN throughput is low

I just migrated from Sophos UTM 9 to Sophos XG Firewall Home Edition. My installation is on an ESXi virtual machine which has 2G memory, 2-core and 2 Intel E1000 NICs. The old UTM 9 had very good LAN to WAN throughput. In my iperf3 tests, it reached to 800+ Mbps. But Sophos XG Firewall has way worse performance: I was unable to get more than 300M bps.

I've tried several ESXi drivers.  Seems driver matters. Since the NICs are Intel E1000 compatible desktop ethernet card, I have 3 options in ESXi 6.0: E1000, E1000E,  andVMXNET 3.  Sophos XG Firewall works with all these drivers. But E1000E and VMXnet 3 can only have a consistent of 133M bps. E1000 is better but still around 300M bps.

The ESXi hosts several other servers which need the NICs too, therefore I am unable to try NIC passthrough.

Anyway I can tune the server to get closer to the throughput of Sophos UTM 9? 



This thread was automatically locked due to age.
Parents
  • Just found out the cause. It is not NIC related. It is the intrusion prevention. If policy is set to None, the throughput is easily jumped to 800+ Mbps in my env.

    Just wondering why UTM 9 has a so efficient intrusion prevention implementation?

Reply
  • Just found out the cause. It is not NIC related. It is the intrusion prevention. If policy is set to None, the throughput is easily jumped to 800+ Mbps in my env.

    Just wondering why UTM 9 has a so efficient intrusion prevention implementation?

Children
No Data