Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Horrible Website Loading Speeds with Content Filtering / IPS enabled

Hi everyone,

I'm posting here as a last-ditch effort before I return my Sophos XG products for a refund and go with Meraki or Sonicwalls.

Over the last week or so, I have been receiving complaints from my client stating that their internet speeds are painfully slow. I ran a speedtest from speedtest.net and they were getting 100 down / 10 Up, so it's not an issue with download speeds. I verified the issue is it can take 6-10 seconds to load a website. Websites that are especially graphics-heavy or secure, such as banking websites, seem to take the longest. (HTTPS scanning and HTTP scanning are disabled)

I spent some time troubleshooting the problem and determined that the problem goes away when I turn off "Default Workplace Policy" and "LAN to WAN" IPS policy. BOTH of these are combining to cause the slow speeds. For example, if I only turn on Default Workplace Policy (and leave IPS off) what it will do is take 3-5 seconds to load all of the content on each website. I.E. it will load the content in small chunks, such as images etc. An interesting thing to note is even when "Allow All" is selected, it still takes this long. I have to select "none" for the speeds to improve.

When I turn OFF "Default Workplace Policy" and turn on only the IPS, then it takes 3-5 seconds to start loading the website. It will be stuck at "Establishing Secure Connection" or "Resolving Host" for that period of time then it will load the page quickly after the initial 3-5 second waiting period. If I turn both off, the page loads in 0.5 seconds.

I understand there are tweaks I can do to improve the IPS speeds but there seems to be nothing I can do about the content filtering... except turn it off.

Before I return these Sophos products, I wanted to reach out to the community to see if there was anything I can do.

Note, this happens on both my Sophos XG125 (serving 12 users), and Sophos XG105 (serving 3 users). The CPU on both is usually around 10% and memory around 50%. The only option is to turn IPS and content filtering off.... which is a horrible solution.  This Sophos product has caused me nothing but problems since I bought it.

Thanks,

Chris



This thread was automatically locked due to age.
Parents
  • Chris,

    can you share your policy settings? Also which DNS servers are your client using?

    Provide us more information on your configuration.

    Thanks

  • Hey Luk,

    Screenshots below.  Running a barebones LAN to WAN policy but as soon as I turn either "Default Workplace Policy" or "LAN to WAN" IPS policy, website loading speeds slow to a crawl.  I think the Default Workplace Policy causes the biggest hit. 

    Workstations use the XG125 as their DNS server, however I have also set it to 8.8.8.8 (Google) to no avail.  I haven't tried rebooting the XG125 but it's only been online for 4 days... can't imagine it being a reboot issue.  Even when I set Content Filtering to "Allow All" the problems start... they only go away when I select "None".

    I have tried disabling all policies except LAN to WAN and it did not help.  Is it normal for Content Filtering / IPS to slow down website loading speeds so darn much?  Ever since I turned it off I've been getting praises from my client about how fast it is.  As soon as I turn on even one of those two features, the complaints come rolling in...

    Screenshots:

Reply
  • Hey Luk,

    Screenshots below.  Running a barebones LAN to WAN policy but as soon as I turn either "Default Workplace Policy" or "LAN to WAN" IPS policy, website loading speeds slow to a crawl.  I think the Default Workplace Policy causes the biggest hit. 

    Workstations use the XG125 as their DNS server, however I have also set it to 8.8.8.8 (Google) to no avail.  I haven't tried rebooting the XG125 but it's only been online for 4 days... can't imagine it being a reboot issue.  Even when I set Content Filtering to "Allow All" the problems start... they only go away when I select "None".

    I have tried disabling all policies except LAN to WAN and it did not help.  Is it normal for Content Filtering / IPS to slow down website loading speeds so darn much?  Ever since I turned it off I've been getting praises from my client about how fast it is.  As soon as I turn on even one of those two features, the complaints come rolling in...

    Screenshots:

Children
No Data