Symantec Web Gateway (SWG) 4.5.x adds more than 2ms latency to an internet connection while in inline mode

Article:TECH96939  |  Created: 2009-01-21  |  Updated: 2009-01-30  |  Article URL http://www.symantec.com/docs/TECH96939
Article Type
Technical Solution


Issue



While directing traffic through SWG 4.5.x in inline mode, you notice that you have slow connectivity. You seek steps to troubleshoot and resolve this behavior.

Symptoms
Slow surfing or other slow network communications from end users to the internet
  • On the case of SWG 4.5 Appliance, the bypass mode light is not lit.
  • In the web interface, on Administration> Configuration> Network, "Service Enabled" is checked.

Conditions
  • SWG is in inline mode.
  • SWG has at least one policy with an action of Block, or SWG's default mode is Blocking.



Solution



  • If slow connection symptoms affect all users and all sites, troubleshoot for all users and all sites.
  • If slow connection symptoms affect only some users and/or some sites, troubleshoot for some users and/or some sites. Then, if symptoms persist, troubleshoot as if connections are slow for all users and all sites.


To troubleshoot slow connectivity for all users and all sites
  1. On the left pane of the web interface, under Administration, click Configuration.
  2. At the top, click Operating Mode.
  3. Uncheck "Service Enabled".

    If symptoms persist, stop here. SWG is not responsible for the slow connectivity. You will need to examine other environmental factors.
  4. On the left pane, under Administration, click System Status.

    If you see CPU utilization over 80%, please contact support for further assistance.
  5. On the left pane, under Administration, click Configuration.> Network. Scroll down to "Ethernet Port Configuration".

    Confirm with your network administrator that the Speed and Duplex for each interface matches the Speed and Duplex of the network device to which you connect.
  6. If necessary, force network speed for one or more interfaces (see below)
  7. Under "Static Route Configuration", check static routes to confirm that you have the correct static route for each subnet in your environment.

    If necessary, confirm with your network administrator that the static routes as they appear in the web interface are correct and complete for the location where you have deployed the SWG Appliance.


To troubleshoot slow connectivity for some users and/or some sites
  1. On the web interface, click Policy> Whitelist
  2. Click Add a Whitelist Entry
  3. If connections are slow for a user, type the IP address of the end user's computer.
  4. If connections are slow for some users, type a CIDR notation for the subnet which contains the end users' computers.
  5. If connections are slow for a site, type the IP address or domain name of the target site.
  6. If connections are slow for multiple sites, type a CIDR notation for the subnet which contains those sites.
  7. Under Comment, type a label for your later reference
  8. Click Save.
  9. Re-test network connectivity. If symptoms persist, SWG is not responsible. Further troubleshooting should focus on the end user's computer or the target website.
  10. Ping from the end user's computer to SWG
  11. Ping from SWG to the end user's computer
  12. Ping from SWG to the target site.
  13. Traceroute from the end user's computer to SWG
  14. Traceroute from SWG to the end user's computer
  15. Traceroute from SWG to the target site


To force network negotiation to 100MB and Full Duplex
  1. Change Auto-negotiate to "Off", then specify the speed and duplex.
  2. In web interface, on the left pane, click Administration> Configuration
  3. At the top, click Network
  4. Scroll down to the section "Ethernet Port Configuration"
  5. For the port you seek to change, on the Auto-Negotiation column, select "Off" in the dropdown box.
  6. --- the Duplex and Speed values become selectable
  7. On the Duplex column, select "Full"
  8. On the Speed column, select "100Mb/s"
  9. Click Save.





Technical Information

About CPU usage statistics
The web interface updates the CPU usage statistic once every 60 seconds.

About auto-negotiation for SWG
Currently, SWG 4.5.x auto-negotiates 100MB/sec speeds as half duplex. If the web interface show a Speed of "100Mb/s" and Duplex of "N/A", and the switch is set to auto-negotiate a 100Mb/s speed, SWG will negotiate a half duplex connection.




Legacy ID



2009102116243054


Article URL http://www.symantec.com/docs/TECH96939


Terms of use for this information are found in Legal Notices