Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

UTM9 Performance (Bandwidth)

I have just migrated from a Dell T105/UTM8 (2.3ghz Althlon 64x2) to a SuperMicro SYS-5015A-EHF-D525/UTM9 (Atom D525 1.8ghz, quad core), and have FiOS 150/150mbps service.

On the old system, I was able to "speedtest" at 80-90bps consistently (and higher than that consistently upload).  On the new system, I'm seeing a pretty hard limit at around 25mbps down, 40mbps up.

If is SSH into the UTM9, I can wget a 100MB file across the internet at 18.1MB/s (~144Mbps).  If I transfer the same file from a client computer, I get about 3MB/s (~24Mbps).  If I do two clients at the same time fetching the same file, the sum of the two data rates is about 4MB/s (~32Mbps).  When this is happening, I see a CPU usage of about 50% on the fw machine.

Is there any tuning I can do?  The hardware and network are clearly capable of doing ~144Mbps, but nowhere near that is passing through the fw to clients.  I think I can do better with this hardware -- i've seen pfsense benchmarks using this hardware that is capable of doing as high as 400-500Mbps.

Help?



This thread was automatically locked due to age.
Parents
  • The issue is your atom, too slow to use with IPS enabled. Very simple to quote William, you need megahertz, many of them, not cores. Over 3ghz for the sort of performance you are looking for.
    Please search the old Astaro forums for posts by William, he has done a great deal of work on this subject.

    I seem to be repeating another post in this thread. 2.2ghz might not be enough?

    Ian
Reply
  • The issue is your atom, too slow to use with IPS enabled. Very simple to quote William, you need megahertz, many of them, not cores. Over 3ghz for the sort of performance you are looking for.
    Please search the old Astaro forums for posts by William, he has done a great deal of work on this subject.

    I seem to be repeating another post in this thread. 2.2ghz might not be enough?

    Ian
Children
No Data