Bandwidth meter for SD-WAN routes is unreliable.

Hello!

At first, I don't know if this is a known bug for the Sophos team, since I couldn't find It on the "Known Issues List".

The bandwidth meter for the SD-WAN routes doesn't show the correct bandwidth that went through each route. This is only an interface issue, the routing itself works as expected.

As an example I've created two rules, one with FQDN's and another with Application Objects, both does the same thing which is send OneDrive traffic to a high bandwidth link.

After downloading >12GB of data, both meters are showing only some megabytes of data went through those rules, looking over the Firewall logs it shows otherwise.

Thanks!

Top Replies

  • On the example above there's no need to use FQDN's or App objects, even with a "Any" destination you can replicate It.
    If I download some data from OneDrive, which passes through either Route #5 or #3, the meter will only account the uploaded data from the client, the downloaded data which went to the same route isn't accounted to the meter.

    That is correct. Only uploaded data from client will show up, as there is no reply direction SDWAN route configured and SFOS accounts SDWAN-route data direction wise.

    I've uploaded 2 GB of data to OneDrive and while checking the Logs, I saw all data went through Route #3, but even then the bandwidth that the meter showed didn't match the amount of traffic that went through. (Not even close.)

    First connection from an app is routed using default wan link load balance. The application-based SD-WAN route applies to subsequent connections after Sophos Firewall learns the session details.

    It seems in your case, appcache hasn't learned (or it had aged from appcache) about ip-addresses of onedrive's storage lakes. That's why missing accounting. Had it been subsequent uploads they should get accounted.

    There is a nice documentation over here.

    https://docs.sophos.com/nsg/sophos-firewall/18.5/Help/en-us/webhelp/onlinehelp/AdministratorHelp/Routing/SDWANPolicyRouting/RoutingSDWANPolicyRoutingUserApplication/

    Hope this clarifies your query.

    HTH

    Moheed

    Jump to answer
Parents Reply Children
No Data