Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Sophos UTM with VMware View PCOIP

Hi,

We're using sophos utm firewalls with our VMware View infrastructure using PCOIP UDP 4172.

However when we use PCOIP we're receiving network loss and delays, when we bypass the sophos utm it's completely fine! We've enabled QoS for PCoIP in the utm but this makes no difference.

What else would be causing the utm to add packet loss to PCOIP?


This thread was automatically locked due to age.
  • Hi,

    is View used at all over the WAN?

    Whenever we play any video's or GFX our FPS in View drops to 1-4 resulting in poor performance, however when we do this without the Sophos UTM everything is perfect.
  • You said that the IPS log showed no attacks, but did it show any anti-DoS-flooding activity?

    Cheers - Bob

    Sorry for any short responses.  Posted from my iPhone.
     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
  • I know, this is an old thread.

    We recently had this same issue at a customer.  ASG120 rev4 with current up2date.

    When they hit about 8 PCOIP sessions, it just started to crawl.  As a diagnostic we disabled everything, IPS, Port scanning, Web filtering, Mail filtering, etc.  If it had an off switch we turned it off.  We even moved the firewall rule to the top spot (which seemed to help a little bit).  And made the rule into an "any" rule to make sure.

    We then noticed, that even while the 8 PCOIP sessions where crawling, we could connect to a 10th machine with RDP (which is tcp) and it was fast and latency free.  Speed test showed that bandwidth and latency to other sites was still good to.  Peak bandwidth was fairly low at around 2-3 Mb/s.

    As a workaround, we have PC's going directly to the cable modem (which has its own basic NAT) and it works beautifully.

    It almost seems like the ASG has a hard time processing the UDP packet stream.  As this doesn’t seem to affect other traffic happening at the same time. 

    Anyone else have issues with UDP based traffic or PCOIP that found an actual fix?
  • Did you check the IPS log for Anti-UDP Flooding activity?

    Cheers - Bob

    Sorry for any short responses.  Posted from my iPhone.
     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
  • Yes, as i noted the IPS was disabled as well as all the DoS flooding turned off.  The logs show nothing as literally every single service that could be disabled was.
  • Did you find a solution? I have the same problem
  • Had same problem, very slow PCoIP connection. Log shows:
    2016:11:24-09:29:35 sgxx-2 ulogd[20489]: id="2105" severity="info" sys="SecureNet" sub="ips" name="UDP flood detected" action="UDP flood" fwrule="60013" initf="eth0" srcmac="00:50:56:xx:xx:xx" dstmac="00:1a:8c:xx:xx:xx" srcip="192.168.xx.xx" dstip="10.168.xx.xx" proto="17" length="96" tos="0x00" prec="0x00" ttl="128" srcport="4172" dstport="50002"

    Had disabled udp-flood-protection at the moment. Problem gone, so as a quick workarround.

    Best regards

    Alex

    -

  • Same issue here.  Also resolved by disabling UDP flood protection on that link.

    -------------------------------

    Interesting [in-ter-uh-sting, -truh-sting, -tuh-res-ting]

    A word typically used by IT technicians to describe an issue they didn't expect, or never encountered, and don't know how to fix.

Share Feedback
×

Submitted a Tech Support Case lately from the Support Portal?