WSS Agent performance concerns with speed test results
search cancel

WSS Agent performance concerns with speed test results

book

Article ID: 407316

calendar_today

Updated On:

Products

Cloud Secure Web Gateway - Cloud SWG

Issue/Introduction

Users accessing internet sites via Cloud SWG using WSS Agents, SEP or ESA agents without issues.

When running speed tests, the performance difference when WSS Agent, SEP or ESA agents is enabled and disabled is noticeable. 

All agent hosts speed tests report throughput numbers that are much lower than line speed.

Performance difference visible with both upload and downloads of files to sites.

No users reporting any issues accessing Web sites/services despite the lower than expected throughput numbers.

 

Environment

WSS Agent.

SEP Web and Cloud access prottection agent.

ESA agent.

Cloud SWG.

Cause

Cloud SWG protects you and your data from online threats by routing your web traffic through our cloud-hosted secure proxies. You might notice that speed tests conducted on a device secured by Cloud SWG show lower speeds than without the filter. This is normal. Although the speeds through the service are lower, they are sufficient to provide a high quality user experience.

The vast majority of online applications provide an excellent user experience with only 20 Mbps of bandwidth. This includes the ability to stream 4k “Ultra HD” video and participate in high definition video conferencing sessions.

Currently, Zoom and Webex indicate that the required bandwidth to participate in an HD video call is less than 5 Mbps. Netflix recommends 15 Mbps to stream 4k “Ultra HD” video. These multi-media apps are generally considered the most demanding that users will encounter and therefore serve as a good benchmark for what constitutes a usable connection.

Resolution

We recommend opening support requests for cases where speed tests indicate less than 20 Mbps or if end user productivity is materially impacted.

Additional Information

The goal of a speed test is to saturate a link with as much traffic as possible to help users understand whether or not they are getting the bandwidth they pay for. The performance delta between Cloud SWG bandwidth and “raw” last mile bandwidth is a result of several factors including changes in packet routing, encryption overhead, and of course, the security operations applied to your traffic per your policies. For example:

  1. A proxy terminates the original TCP/IP connection and creates a new connection. This process dramatically improves security posture but impacts performance.
  2. Scanning proxies buffer file downloads and uploads in order to scan files for malware and data leakage. To an end user, this process can look like the file is transferring slowly while it’s being scanned.
  3. Customer policy complexity affects performance.