Hardware Offloading | Sophos XG

nicedevil

Member
Aug 5, 2021
110
10
23
Hey Guys,

I'm running my PVE on a 8 x 11th Gen Intel(R) Core(TM) i5-1135G7 with "in my opinion" enough power to virtualize my Firewall (Sophos XG at the moment, will be Fortigate in the near future). I already was able to switch the better performing Openvswitch but I'm not getting as much bandwith as I'm able to get by my ISP.
I already checked my speeds with a direct connection from my Laptop to the Modem of my ISP (having the full 900-1000 Mbit downloadspeed).
If my environment is running behind my Sophos XG it all drops down to max 300 Mbit if I'm lucky, most of the time I'm sitting at 100 Mbit.

Now I started reading here and there about "deactivate hardware offloading". Most threads are about pfSense/OpnSense installations.
So I was going to my PVE WebUI and tryed to find that setting anywhere. You guess it, I didn't find it (is that a setting that is only available on pfSense? or am I just a bonehead?).

Passthrough of the NICs seems not to be a proper solution because my SATA drives will start sending errors after I activate it.

Just to clear this up before anyone asks: the firewall got 2 cores with 4 gb of ram and nothing of it seem to be used as much as there should be a bottleneck (max 10% CPU load, max 50% memory).

1654713473590.png

Any advice? And as always, thank you in advance.

EDIT: Here my hardwareconfig:
1654714379586.png

Networks on my host:
1654714406733.png

vmbr1 => WAN
 
Last edited:
I suppose a key question would be what is the 'real' nic on the host?

Interesting that you've chosen to go with OVS in preference to the proxmox default - not sure it's relevant but then again it may be.

All I can usefully offer is that 'intrinsically' there's no reason why you shouldn't get at least 90%+ of the potential performance - I manage three sites with Gigabit internet, all running pfsense as a VM, with full WAN-to-LAN speeds

I assume your host-to-lan speeds are as expected?
 
  • Like
Reactions: nicedevil
All of the NiCS are Intel 1 Gbit NICs, if you need the right type of them I can post later.

My host is connected to a 10 Gbit Unifi switch and that one is connected to my PC f.e.

The speeds here are as expected. Tested with a samba share on copying a huge ISO file.

The OVS thing was the first part with found that should perform much faster than the default Linux bridge. I solved the problem not at all just got around 50-150Mbit more Speed for WAN. Ethernet Speed for local transfers were as high as they are right now with OVS.
 

About

The Proxmox community has been around for many years and offers help and support for Proxmox VE, Proxmox Backup Server, and Proxmox Mail Gateway.
We think our community is one of the best thanks to people like you!

Get your subscription!

The Proxmox team works very hard to make sure you are running the best software and getting stable updates and security enhancements, as well as quick enterprise support. Tens of thousands of happy customers have a Proxmox subscription. Get yours easily in our online shop.

Buy now!