Routing – SonicWALL NSA 220 degraded egress performance

firewallroutingsonicwall

We have a SonicWALL NSA 220 running SonicOS Enhanced 5.8.1.2-20o. Our ISP provides a symmetrical 100/100 ethernet handoff. Performance on the ingress achieves the full 100Mbps while egress only achieves ~30-40Mbps. What am I not considering in troubleshooting this? Is there anything that might cause this type of asymmetry in performance?

Here is what I have done so far:

• Disabled auto-negotiation on WAN interface and coordinated hard coded 100/Full Duplex setting on ISP gateway

• Confirmed MTU is 1500 bytes on all devices on the local ethernet

• Confirmed MTU is 1500 bytes on firewall and ISP gateway and ISP next hop

• Confirmed all services are disabled on SonicWall (including CFS, DPI, BWM, LB, etc.) – it is pretty much just running a stock configuration minus some port forwarding rules

• Observed high CPU utilization (65%-95% for periods in excess of 10 minutes under a relatively light load 58 connections)

Best Answer

The issue was resolved by updating the firmware. Firmware was updated to 5.9.x.