on 06-09-2023 07:01
I recently upgraded my broadband to M600 but continued to get download speeds in and around 125Mbps. I am running a Unifi Network with the VM hub connected directly into a Unifi USG 3P, which goes into a Unifi 24 port switch. My wifi AP’s run off the switch and I also have a Unifi CloudKey connected.
I contacted Virgin Media Tech support about this yesterday and they ran some diagnostics, but they couldn’t really tell me a lot because the Hub was in modem mode. During the phone call the call handler got me to switch the hub into router mode, so that they could complete their diagnostics, and they couldn’t see a fault. While they were on the phone I connected directly to the hub while it was in router mode and ran a speed test, and got the speeds I expected. This was a real success and proved that the download speed issue was my side.
After the call with VM I went onto the Unifi community pages and searched up ‘USG speed throttling’ and from what I read, all of the posts advise to activate the all of the ‘Hardware Offload functions’. Last night when I checked I couldn’t activate Hardware Offload (the option was greyed out) but this morning I tried again and I was able to activate all of the offload options, and I am pleased to report that my download speed remains really good and as expected.
Just wondered if anyone else has experienced similar and whether there are any other settings I should be adjusting on my Unifi network to optimise it further?
Answered! Go to Answer
06-09-2023 18:41 - edited 06-09-2023 18:53
Turn off IDS/IPS - it's currently called "suspicious activity" in the latest version of unifi but has previously been called "threat Management". the USG is an older hardware and can only run IDS/IPS at about 85 mbps originally (but can now manage about 130mbps) as it was not really designed for it. if you want real time threat analysis and blocking you would need one of the newer UDM Pro or UDM SE. They are in the process of updating the USG with a UXG (not the UXG-PRO) that might do the trick - that product hasn't been released yet but you would be able to swap it in and continue using the cloud key.
and as in the post above, you can disable DPI too, although i think the usg can manage 1gbit speeds with DPI enabled with the latest firmware and software.
on 06-09-2023 09:15
I believe on a USG you need to turn off DPI (deep packet inspection), but I have read it is only necessary if you are on 1G. I’m a UDM-Pro user myself and with all the latest updates and can highly recommend Ubiquiti/UniFi equipment.
06-09-2023 18:41 - edited 06-09-2023 18:53
Turn off IDS/IPS - it's currently called "suspicious activity" in the latest version of unifi but has previously been called "threat Management". the USG is an older hardware and can only run IDS/IPS at about 85 mbps originally (but can now manage about 130mbps) as it was not really designed for it. if you want real time threat analysis and blocking you would need one of the newer UDM Pro or UDM SE. They are in the process of updating the USG with a UXG (not the UXG-PRO) that might do the trick - that product hasn't been released yet but you would be able to swap it in and continue using the cloud key.
and as in the post above, you can disable DPI too, although i think the usg can manage 1gbit speeds with DPI enabled with the latest firmware and software.
on 09-09-2023 08:03
Thanks for the reply and all of the information you provided.
With IDS/IPS turned on, I only get around 150 Mbps. With IDS/IPS turned off, I get around 600-630Mbps - I cant believe the difference, and needless to say IDS/IPS will be left switched off.
I also ran some speed tests with DPI turned on and off, and this didn't have a big affect on download speed, so I intend to leave this on.
I'll have a look at the UDM Pro and UDM SE and also see if I can find any info about the new UXG. Thanks again for your help.