Hate to bump this thread, but I am definitely getting these symptoms. I tried changing the config file and the connection setting in the utm to UDP using port 443, but at that point I could not connect at all.
I have tried on two laptops and I am getting the 10mbps connection. It is so slow I have an in house program that creates quotes for our on the road sales person to get to clients, but the program locks and will not display any information. Connected to the inside wifi it works flawlessly. Over the VPN he can get his email and get to network folders, but it is very slow.
Upon creating the VPN for him, I did not check speeds, but I do remember everything working. He says it has progressively gotten worse.
I tried to make exceptions in IPS for the VPN pool, but that seems to have no effect.
Firmware ver. 9.211-3 Have updates available, but a little reserved on installing them as last time it screwed up a few things that took me a few days to get straightened out.
We have created an IPS->Exception for UDP Flood Protection (disabled) for all UDP connections on that specific SSL-VPN Port and Interface/IP we use for it and now we get the full 100Mbit/s to the datacenter for downloads and about 6-7Mbit/s upstream to the datacenter where both was limited to 2Mbit/s before (with UDP Flood enabled for everything).
Hope it helps!
[:O]
I tried everything, and I decide to switch to Cisco VPN Ipsec\UDM and is looks like much better , i get in download speed 15-18 on line 25 .
Im in Manitoba and line from MTS to Shaw is sucks, from Shaw to Shaw all perfect.Some internet providers try decrypt traffic ....
We have the same exact problem with a SG230, the SSL VPN seems limitted to 10Mbps even though we have 300/100Mbps in the remote site where the firewall is and 100/10 in the office.
The current configuration is UDP, no compression, SHA2 256, Key size 2048 bit, AES-256-CBC. We have tried TCP and other combinations with the algorithms with no luck. IPS and flood protections are disabled.
Jon, what result do you get withSHA1, 1024 and AES-128-CBC? Watch the Intrusion Prevention Live Log when you try.
Cheers - Bob
Actually, it was the other things in that log that might be of interest. Snort rarely causes these issues, but Anti-DoS Flooding can.
Cheers - Bob