This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

[Sophos Notification] Sophos XG Firewall: ​IPS causing drops to legitimate traffic and filling the IPS log

Hi Community,

[Update 2]: This issue has been fixed in SFOS v17.1.4 MR-4.

[Update 1]: Please also see post below.

Some customers on SFOS v17.1.3 MR-3 are experiencing an issue where IPS is causing legitimate traffic to be dropped and the IPS log to be filled.

If you are experiencing these issues:

  • Please login to the XG via SSH and go to the following options:
    • Option "4. Device Console":
    • Then run command: set ips tcp_option detect_anomalies disable

The fix for this is scheduled to included in the upcoming SFOS v17.1.4 MR-4 release. Please stay tuned for more information.

KB article has been published for this issue.

Regards,




[locked by: SupportFlo at 3:07 PM (GMT -8) on 20 Nov 2018]