This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

XG 310 problem - YouTube buffering, poor peformance HD streaming

Hello,

I am trying to figure out if I have a configuration problem that is causing YouTube buffering when users are trying to watch at HD resolutions. I am unsure if the issue is actually the XG firewall or possibly might be related to our ISP, AT&T. However, I'm going to assume firewall for now as I have no reason to suspect the ISP. First off, I'm still learning my XG 310 so I might not be understanding of certain features.

The problem: users are seeing erratic performance when viewing YouTube content especially when in HD mode or 4K. Buffering, stalled playback, etc. When checking the firewall during these times, we are nowhere near our bandwidth limits, plus CPU (4-6%) and memory usage (28-34%) are all low. The frustrating thing is that sometimes the videos will playback with no issue at all. Perfect. Other times the problems. Conversely, when comparing against say Netflix, we have no issue at all in playing back through that service.

I have created a Web filtering exception with the following URL matches:

Matching URLs:
^[A-Za-z0-9.-]*\.ggpht\.com\.?/
^[A-Za-z0-9.-]*\.googlevideo\.com\.?/
^[A-Za-z0-9.-]*\.youtube\.com\.?/
^[A-Za-z0-9.-]*\.ytimg\.com\.?/
 
I am bypassing all scanning features: HTTPS Decryption, Malware Scanning, and Policy Checks. We do not have the Sandstorm feature.
 
 
At this point I am stumped on what I need to do next or what is lacking. I have tried to use logging to narrow down my search but I'm not sure how/what I should be looking for or logging exactly. I was thinking maybe the web proxy cache might be related? But other than the 'Restart' button, I'm not sure what I can control on that feature.
 
So any advice or suggestion is much appreciated. Let me know if you need other/different information.
Thanks!
RH


This thread was automatically locked due to age.
Parents Reply
  • Its much less. Most streaming services work fine now but fast forwarding is still an issue. It takes time to buffer. I am more and more convinced this is a bufferboat issue. Just not sure how to solve it. I hope Sophos community members that have resolved the bufferbloat issues are able to draft a simple guide.  

Children
  • Hi,

     

    can you explain in a few sentences, how to reproduce it?


    Another point: Best case in such an scenario: Build new policy on top : Testclient with any services to WAN. Disable all the security features like Proxy, IPS, AppCtlr etc. and test it again. Afterwards enable in this test policy the features and try it.

    If you are able to get closer to the affected module, we can try to find a solution.

    This is how i troubleshoot my appliances.

     

    Cheers.

  • Do you have udp 443 enabled or only tcp?

    Google seems to more and more be preferring udp these days, it is about 20% of our Google traffic now.

    Cheers,

    Charles

  • Google using UDP is the QUIC protocol, and anything using it is not scanned by the proxy.

    In 17.1 there will be checkbox to easily disable/block QUIC so that it falls back to normal traffic.