Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Is this normal? UTM 9 home reducing ISP performance significantly

Hello,

I'm not a Sophos expert like many of you but I knew that it was a great value to be able to leverage enterprise grade firewall technology at a home. I signed up for and received the home license for UTM and installed it on a Zotac ZBOX-CI325NANO its got a quad-core intel celeron processor, 120gb SSD and either 4 or 8 gb of ram. When I had Comcast 100mb service I consistently received that speed at my end point devices. Comcast Gig recently became available and I decided to sign up. When I connected to the modem directly with my laptop I was able to get 940mb (although only from Comcasts own speedtest.xfinity.com website. If I plug my firewall in to the modem and connect directly to the firewall (with no switch) my speed drops to 500 mb on that same speedtest site. I check my firewall dashboard and the performance metrics all look good (low utilization on CPU, Memory, disk etc.). Does anyone have any advice on how I can get the most performance out of this? What optimizations could I make? Where do you think the bottleneck is? Obvious suggestions are ok too because I'm obviously not as practiced with this device as many of you. Thanks!



This thread was automatically locked due to age.
Parents
  • Welcome to the gigabit club.

    First off read this thread https://community.sophos.com/products/unified-threat-management/f/general-discussion/22065/rulz .  Commonly referred to as 'rulz' on here.

    As you'll discover soon (or have already) utm is based on the premise of block everything first then create rules to allow data in and/or out.  Keep this in mind.

    That said, having web filtering and ips enabled will slow throughput.  To confirm this, without making any other changes, turn both off and repeat your speed tests. Expected result will be full throughput.  I use web filtering and ips (intrusion protection) enabled with exceptions for several speedtest sites and a few other high bandwidth services. My exceptions are based on ports and actual destination FQDN's configured as DNS groups (because some hosts have multiple ip's).

    I use a qotom q355g4 which is i5-5250u based with 8gb of ram.  This handles gigabit quite well.  If you want to leave all the protections fully enabled, you'll need much more processing power.  Hope this at least points you in the right direction.  I'm still fighting some of my own gremlins here.

     

    Edit: Minor clarifications.

Reply
  • Welcome to the gigabit club.

    First off read this thread https://community.sophos.com/products/unified-threat-management/f/general-discussion/22065/rulz .  Commonly referred to as 'rulz' on here.

    As you'll discover soon (or have already) utm is based on the premise of block everything first then create rules to allow data in and/or out.  Keep this in mind.

    That said, having web filtering and ips enabled will slow throughput.  To confirm this, without making any other changes, turn both off and repeat your speed tests. Expected result will be full throughput.  I use web filtering and ips (intrusion protection) enabled with exceptions for several speedtest sites and a few other high bandwidth services. My exceptions are based on ports and actual destination FQDN's configured as DNS groups (because some hosts have multiple ip's).

    I use a qotom q355g4 which is i5-5250u based with 8gb of ram.  This handles gigabit quite well.  If you want to leave all the protections fully enabled, you'll need much more processing power.  Hope this at least points you in the right direction.  I'm still fighting some of my own gremlins here.

     

    Edit: Minor clarifications.

Children
No Data
Share Feedback
×

Submitted a Tech Support Case lately from the Support Portal?