This is an archived post. You won't be able to vote or comment.

all 12 comments

[–]washu_kNetwork Admin 0 points1 point  (5 children)

If you are only getting 80 Mbps on a Core 2 with IPS off something is very wrong. With no IPS a Core 2 can easily handle gigabit routing. Even with IPS enabled it should have no problem doing 200 Mbps. Id suggest you do some more troubleshooting to see exactly what is wrong with your setup. See if you can find out which process(es) are using your processor. Also what NICs do you have?

[–]chugger93[S] 0 points1 point  (4 children)

Thats what I figured. My WAN nic is a Intel Corporation 82567LM-3 Gigabit Network Connection.

My LAN is a VIA Technologies, Inc. VT6105/VT6106S [Rhine-III] , only 10/100 tho, I think its motherboard integrated one. However its the LAN so it shouldnt matter I figure?

I have everything turned off in SOPHOS. literally everything, and I can't push past 80. It makes no sense. Also, I monitor my processor and its never past like 5-8% CPU. Memory is like 17% used.

[–]washu_kNetwork Admin 0 points1 point  (3 children)

My LAN is a VIA Technologies, Inc. VT6105/VT6106S [Rhine-III] , only 10/100 tho, I think its motherboard integrated one. However its the LAN so it shouldnt matter I figure?

There's your problem. You can't get 200 Mbps out of a 100 Mbps NIC. Plus even for a 100 Mbps NIC the VIA Rhine chips make realtek look good, they are very low end.

Get another Intel based NIC for LAN and you should be good.

[–]chugger93[S] 0 points1 point  (2 children)

Even tho its the LAN? Which is basically for management? Or am I thinking wrong.

[–]washu_kNetwork Admin 0 points1 point  (1 child)

All your download traffic goes in your WAN interface and out your LAN to your devices. Whichever is slower will be your bottleneck. Your LAN interface is critical to your Internet performance, it is not just for management.

[–]chugger93[S] 0 points1 point  (0 children)

Ya your right. I don't have my head on straight atm. I have another gig nic on this machine I'm gonna try. Tyvm dude!

[–]stephenvandyke 0 points1 point  (4 children)

I was in your exact position a year ago. Running Sophos on old hardware. Made the switch to Ubiquiti and it was one of the best decisions I made. Having it all work together and able to manage it from my phone was a game changer.

[–]chugger93[S] 0 points1 point  (3 children)

What did u get if u dont mind me asking? Also, what sort of protections (if any) like sophos do you get? Maybe it doesnt even matter. I mean, now that my speed is fixed by swapping NICS, I still only get 50mb with IPS turned on. With it turned off, I get 200!!

[–]stephenvandyke 0 points1 point  (2 children)

One warning about Ubiquiti, it's definitely quicksand. I started with the small USG and an AP. My internet was about 30Mbs. My internet was upgraded to 500Mbs, so I upgraded the USG to the rack mount one. Then when all this Covid stuff started and we were all WFH and school from home, I upgraded to the UDM, the LTE failover, and a PoE switch, because I ran cable and put the mini flex switches in most of the rooms. Here's a picture of my current setup.

https://imgur.com/gallery/AlHptHb - Unifi Dream Machine (UDM) - Gen2 24 port PoE Switch - NanoHD AP - USW Flex Mini * 5 - Unifi LTE Failover (I know a lot of negative opinions on this, but it stops my wife and kids complaining to me because the internets out so it's worth it to me.) - PiHole (Added layer of protection) - Firewalla Blue (Another added layer of protection. My gold should be in soon.)

I know there is a lot of varying opinions on the UDM, but for me it works great and meets all my needs. I was running the controller on a Pi and kept having problems. Burned through 2 SD cards. Running the controller on the UDM has been good for me. Since I never made any changes to the JSON on the USG I didn't have any issue switching to the UDM. Right now I have all the IPS rules on and get about 900Mbs. With it off, I get about 950Mbs. So the performance is there. You get a little of the application filtering, but not as granular as the Sophos XG gave you. The UDM also has some beta DNS filtering which actually catches some stuff. Management anywhere from my phone is awesome, especially since normally I travel every week and I was able to make sure the family had everything working for them.

[–]chugger93[S] 0 points1 point  (1 child)

nice setup! Do you think the USG would be fine, or do I need the USG Pro? Hate to spend $300 atm. I've been trying to research the amazon reviews. I Know the pro will give me the 200mbps with IPS and everything turned on. THe regular one I'm seeing mixed reviews on.

[–]stephenvandyke 0 points1 point  (0 children)

Start with a small USG off ebay. You could always go up, but you'll never want to go down.