This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

[Sophos Notification] Sophos XG Firewall: ​IPS causing drops to legitimate traffic and filling the IPS log

Hi Community,

[Update 2]: This issue has been fixed in SFOS v17.1.4 MR-4.

[Update 1]: Please also see post below.

Some customers on SFOS v17.1.3 MR-3 are experiencing an issue where IPS is causing legitimate traffic to be dropped and the IPS log to be filled.

If you are experiencing these issues:

  • Please login to the XG via SSH and go to the following options:
    • Option "4. Device Console":
    • Then run command: set ips tcp_option detect_anomalies disable

The fix for this is scheduled to included in the upcoming SFOS v17.1.4 MR-4 release. Please stay tuned for more information.

KB article has been published for this issue.

Regards,




[locked by: SupportFlo at 3:07 PM (GMT -8) on 20 Nov 2018]
Parents
  • Hi Community,

    If you are experiencing issues related to the following IPS log entries:

    Please attempt the commands provided in the mentioned KBA.

    Regards,

  • I don't see this problem at the moment.

    However, I see the message below on my XG105 and two other customer sites. I have clicked Update Pattern and no change. I know that the latest is v9.15.39.

    Which version is causing the problem? If I do see the issue at customer sites, I can follow above and KB. But I presume this is a temporary fix and Sophos are working on the solution?

     

    IPS and Application signatures
    9.15.36
    -
    15:45:13, Nov 13 2018
    Failed
Reply
  • I don't see this problem at the moment.

    However, I see the message below on my XG105 and two other customer sites. I have clicked Update Pattern and no change. I know that the latest is v9.15.39.

    Which version is causing the problem? If I do see the issue at customer sites, I can follow above and KB. But I presume this is a temporary fix and Sophos are working on the solution?

     

    IPS and Application signatures
    9.15.36
    -
    15:45:13, Nov 13 2018
    Failed
Children