This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Free XG Firewall (Home) install - SPEEDTEST.NET results are poor

Hi,

I'm looking at trying to limit my daughter's (10 years old) internet access. She keeps falling down the YouTube rabbit hole. My current home router limits all access or none. There is no timed limit.  I'd like to have Facetime, iMessage, email and generally google/edu access most of the time and streaming limited to some of the time.  So I started looking at XG Firewall for Home.

Three house members with a total of 20 devices. (Laptops, Pis, Desktop, iPhones etc..)

My question at the moment is more around speed or the lack of when using it.

I've completed a fresh install of XG onto a VMWare Workstation (12.5) running on a Windows 7 host GB single ethernet card. I've given the VM 4 vCPU and 6GB of RAM. Virtual HDD is 20GB on an SSD. 

The VM has two virtual network cards one assigned to LAN the other to WAN.

With this Windows 7 workstation using the standard router gateway, speedtest.net gives me the following speed test results.

Speed without XG

When I change the workstation to use the LAN IP address of the XG FIrewall as the gateway I get the following

Speed results with XG Firewall as the gateway

I'm barely getting one third (1/3) of the usual download speed and the upload speed is only two thirds (2/3) of the maximum available.

Is this the 'home version' limitation? or is it that my VM running on a Windows 7 host and I should be able to easily achieve the speeds I see when I don't use XG.

 



This thread was automatically locked due to age.
Parents
  • Hi,

    first things first, the home licence is not choked in anyway other then max of 6gb and 4cpus. NBN, lucky you.

    I expect that

    1/. your disk allocation is too small, needs at least 60gb

    2/. your windows 7 will be the partial issue, your putting 3 layers of software where there should be one maybe 2. W7 is not a high performance OS, designed for screen not background tasks.

    3/. you really should have minimum of 2 and in your case maybe 3 NICs

    4/. please review the IPS tabs to see if there are any packet drops and if so untick the box and rerun the test.

    5/. you are better off using and old PC with extra NIC cards to at least get you running.

    Ian

  • Hi Ian,

     

    Thanks for the reply. The end goal is to buy one of those Mini-PC with dual NICs that are fanless and have it as a dedicated Firewall running Sophos XG for Home. Just didn't want to spend the money unless I could get it working. 

    Why three NICs? one WAN and two on the LAN side?

  • Hi Justin,

    why 3 NICs on your current setup, one is for the window management and updates, the other two are for XG so you can get your throughput. The W7 machines probably has a realtek nic which is not good for what you are trying to prove.

    With your fanless PC make sure it has intel nics that are not i219 series, they are not supported.

    Ian

  • Hi Ian,

     

    Give that man a cigar - THe W7 box has a Realtek NIC. I think I saw your post on another thread regarding making sure that the NICs are Intel. Many of these Mini-PCs don't clearly indicate what they are. Have any suggestions?

  • If you have a dedicated machine running this, you don't need 3 - two is fine.  The only reason to add a 3rd, 4th, etc. is if you start segmenting networks, need to bundle ethernets, etc. - none of those will apply in a SOHO situation so 2x GE is fine.  

    Regarding PCs, check out Qotom - they have awesome small footprint fanless machines under 200-300 running Celeron CPUs which are more than fine for this task.  I have one running pfSense and the other running XG and both are flawless.

    Have fun...

Reply
  • If you have a dedicated machine running this, you don't need 3 - two is fine.  The only reason to add a 3rd, 4th, etc. is if you start segmenting networks, need to bundle ethernets, etc. - none of those will apply in a SOHO situation so 2x GE is fine.  

    Regarding PCs, check out Qotom - they have awesome small footprint fanless machines under 200-300 running Celeron CPUs which are more than fine for this task.  I have one running pfSense and the other running XG and both are flawless.

    Have fun...

Children
No Data