This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Upload speeds with Sophos totally crippled

I just got a symmetric gigabit connection.  When using Sophos XG, I get close to the full download speeds, but the upload is a fraction what I should get.  

Average with sophos

850

150

Average with another router:

901

1039

I am a bit new to Sophos but I don't have any QOS/Traffic shaping enabled as far as I can tell.  I don't think it's CPU related either because even with the top download speed, im only hitting 80% on the CPU.  I have Sophos running in a VM on an i3-4130 with 4 gb of ram.  Version SFOS 17.0.2 MR-2

Any thoughts on what could be limiting only the upload speed?

EDIT It looks like IPS is the culprit here - disabling it gives me normal speeds.  But that's a big sacrifice to make - why does IPS impact performance so much, especially considering it's not even maxing out my resources?  Is there a way to disable IPS per device, like with Web protection or do I have to make separate firewall rules?



This thread was automatically locked due to age.
Parents
  • Our of curiosity, is that Mbps? If so, I’m surprised how fast of a download you can achieve with IPS. I’m running Sophos XG on a Core i5-5250U with 4GB of RAM and I get 900 Mbps down without IPS and 300 Mbps with IPS enabled. Sophos XG uses Snort for its IPS engine which doesn’t support multi cores like Suricata, so the big limitation is how fast your CPU can work on a single core. The really weird thing is having less rules in your IPS Policy doesn’t seem to make a difference either which I don’t understand at all. I created a custom IPS Policy which took me from over 7,000 rules to approximately 1,500 and my bandwidth test results are the same. My upload isn’t affected but it’s limited to 50 Mbps.

    You have to create another firewall rule and just add those devices that you want to bypass IPS. Creating MAC Hosts for your devices is useful for this if you don’t want to create static IPs.

Reply
  • Our of curiosity, is that Mbps? If so, I’m surprised how fast of a download you can achieve with IPS. I’m running Sophos XG on a Core i5-5250U with 4GB of RAM and I get 900 Mbps down without IPS and 300 Mbps with IPS enabled. Sophos XG uses Snort for its IPS engine which doesn’t support multi cores like Suricata, so the big limitation is how fast your CPU can work on a single core. The really weird thing is having less rules in your IPS Policy doesn’t seem to make a difference either which I don’t understand at all. I created a custom IPS Policy which took me from over 7,000 rules to approximately 1,500 and my bandwidth test results are the same. My upload isn’t affected but it’s limited to 50 Mbps.

    You have to create another firewall rule and just add those devices that you want to bypass IPS. Creating MAC Hosts for your devices is useful for this if you don’t want to create static IPs.

Children