Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Sophos XG85w - SSL VPN works in TCP but not in UDP

Hello,

I got a problem with a SSL VPN remote access, for now the VPN works in TCP but it is very very slow. data transers at 50ko/s with a 50mbit/s internet connection.

 

The VPN is configured with TCP protocol and I want to change it to UDP. When I do the change, client cannot conncect to VPN anymore.

 

Do you have an idea about the problem ? And why in the VPN so slow in TCP ?

 

Thank you



This thread was automatically locked due to age.
Parents
  • Hi Raphaël,

    You need to download again the configuration file for the SSL VPN Client if you change from TCP to UDP. Or you can manually change the configuration from which is stored in C:\Program Files (x86)\Sophos\Sophos SSL VPN Client\config and change the line "proto tcp" by "proto udp".

    Regarding the slow TCP connection, I would take a look at the MTU. You need to go in Network > Interfaces, here you modify your WAN interface and you go into "Advanced Settings", you can lower the MTU, I'd try 1400 and you need to modify the MSS aswell, 40 under the MTU, so 1360 for example.

  • Hi Thibaut,

    Thank you for you response.

    I already download the configuration file with after change the protocole to UDP but it doesn't work.

    For the MTU and MSS and could try to change it. But we'll it impact internet traffic ? And what could be the gain?

    Thanks for you help

  • Hi Raphaël,

    The MTU is the maximum length of a packet over the network. The default value is 1500 and sometimes some Internet connexion can't accept those packet length and are dropping packets that exceed their capacity. This could be a reason for slow SSL VPN. By setting it lower, your Sophos will fragment the packets to smaller ones, that should not impact your Internet traffic.

    Btw, from LAN to WAN, do you experience slow Internet connexion or not?

  • Hello,

    Today, I tried to reconfigure the VPN but there is still the problem.

    The last firmware is installed.

    For now I'm still using TCP protocol and the problem is that the connection with SSL VPN is very slow and unstable. Ping response is between 25ms and 1100ms ! I tried with PPTP and it's worse, I got a timeout each 15 ping...

    The MTU is configured right for our internet connection and internet access from LAN is very good.

    I know that a xg85w is not the Rolls from Sophos but this VPN speed is terrible and I can't increase is... The firewall seems ok with 18% CPU usage and 45% memory usage.

    Does anybody have an idea of the problem?

    Thank you

Reply
  • Hello,

    Today, I tried to reconfigure the VPN but there is still the problem.

    The last firmware is installed.

    For now I'm still using TCP protocol and the problem is that the connection with SSL VPN is very slow and unstable. Ping response is between 25ms and 1100ms ! I tried with PPTP and it's worse, I got a timeout each 15 ping...

    The MTU is configured right for our internet connection and internet access from LAN is very good.

    I know that a xg85w is not the Rolls from Sophos but this VPN speed is terrible and I can't increase is... The firewall seems ok with 18% CPU usage and 45% memory usage.

    Does anybody have an idea of the problem?

    Thank you

Children