09-08-2018 07:24 AM - edited 09-08-2018 07:31 AM
I know this is a long time later. I just got my setup, with USG, switch, etc. I have Google Fiber as well and use it for WiFi until my Amplifi stuff gets here. Anyway, I read through this entire thread and others and I thought surely this has been fixed in the last year. My USG is on 18.104.22.16818795. I tried looking at the IP Offload module via CLI but it is enabled just the services for IPv4 and IPv6 (which I'm not using) are disabled. I'll play with that later. One thing to note if testing from the Dashboard of your controller you will not get your full gig speed because the USG can't produce that much traffic itself. Testing with Ookla from your computer is going to tell you what YOU are really getting more accurately.
Anyway, I found that turning off IPS/IDS took my speeds from about 100Mbps backup to close to 900Mbps on my gig fiber. That said, I'm security focused and can live with 100Mbps for the 2 of us in the house. I have a 50 Mbps fiber at work that serves about 60 people and there is no impediment to being able to traverse the Internet just fine. So, at this point I think I'll leave the JSON alone unless someone has a magic config for improving the IPS/IDS that is killing about 800Mbps of speed. Soon I'll have my Suricata IPS setup and can turn this off, but still that would be something for positive feedback for developers. Big fan, so no complaint, just giving feedback.
If there is a more current thread on this topic, please let me know. This is the main one I could find. Cheers!
Oh, and note that DPI ON or OFF seems to make no difference. It is the IPS/IDS. =)
My ISP offers 250/20 , after several firmware updates to USG 3P speed dropped to about 40/10. ( with ISP OFF, DPI off). I reseted the USG with button on backdoor and adopted USG again. The speed came right back.Simple reset helped! Now with ISP ON it droped to 75/20. With ISP OFF its at full speed.