This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Sophos SG firewall deadly slowwwwwww

I just did a virtual machine ESXi install from the VI-SFOS_17.0.0_GA.VMW-80 virtual image that sophos has on their website using the default values (1 cpu, 2 GB RAM, SSD disk).  I configured all protection on as part of install.  I ran a speediest, and:

- my download speed went down from up to 350Mbps using pfsense and squid to 30Mbps running on the same virtual server.

I then increased CPU to 4 (on a xeon 3ghz machine) and memory to 4 GB.

My speed went up to:

- 75Mbps, and CPU utilization based on the control center maxed out at 11%.

- I disabled ALL scans, and my speed was 280/350 max.

So, I redid an install from scratch on another VM with 4 CPUs and 4GB.  Same performance as from imageVM.

I then installed to a dedicated fanless i5 router box (4 core, 4GB, 30 GBSSD)- another machine.  Without scans, I was able to get my full speed (350/350).  With scans, I only get 40/350.  Again, CPU utilization is around the 10% mark.

Questions:

1. Why doesn't the CPU max out?

2. Does 32bits limit performance?

3. Why on a VM it doesn't hit 350 when all security is off

4. why it can only deliver 40/350Mbps with all protection on and why it doesn't use full potential of CPU

image of cpu usage spike at turn on https://imgur.com/MhGeO1R

config https://imgur.com/RShtcU1



This thread was automatically locked due to age.
Parents
  • Hi,

    minimum is nice in theory, but as you found out not very practical.

    Also turn off ips -> dos protection and try again. Didn't think XG came in 32bit only 64 bit.

    Also what nics are installed? What drivers are you using in the image?

    Ian

  • Thanks for your time.

    The VM is listed as OS Other, 32 bits in esxi.  So I'm wondering if this is an issue.

    I'll test again with IPS off and post results.

    I have a Dell Intel Gigabit ET Multi-Port Server Adapters H092P on my Dell T20 ESXi host and kept the default drivers in the image (AMD Lance PCNet 32).  I'll change to E1000 and retest if turning off DOS increases speed.

    The Qotom mini-pc has built in intel nics.

Reply
  • Thanks for your time.

    The VM is listed as OS Other, 32 bits in esxi.  So I'm wondering if this is an issue.

    I'll test again with IPS off and post results.

    I have a Dell Intel Gigabit ET Multi-Port Server Adapters H092P on my Dell T20 ESXi host and kept the default drivers in the image (AMD Lance PCNet 32).  I'll change to E1000 and retest if turning off DOS increases speed.

    The Qotom mini-pc has built in intel nics.

Children
No Data