I get thousands of this alerts every time I use https://www.speedtest.net/
Does it make sense? how can I disable it or fix the issue?
This thread was automatically locked due to age.
I get thousands of this alerts every time I use https://www.speedtest.net/
I have applied this solution
https://community.sophos.com/kb/en-us/133096
Now not only I dont get those alerts, I have full speed on upload 300Mbps with this setting enabled I got around 260 Mbps and thousands of alerts
For the firewall rule affected I only have web filering.
I only have IPS active in a rule that only affect to a host, so the speed test has nothing to do with it
The only way to get 300 Mbps of upload is if I stop the IPS service completetly in "System Services" -> "Services"
It looks like a wrong implementation of Snort in Sophos XG, how my upload speed can be capped if I dont have the IPS active in any rule?
Hi Flo,
my apologies, I took that comment out after much testing and could not see any changes to my download speeds using speediest.net.
Further my settings for the IPS are not the default, but updated from previous recommendations on how to block some unwanted software/access.
What Idid find was that limiting the speediest.net to its FQDN sites caused it to fail, but no restrictions on download or upload performance.
I will run some more tests with IPS enabled in the speediest rule and report back.
Ian
Update on testing.
My IPS settings had no affect on the speedtest.net performance. I have tuned my IPS policy.
Using http/s as the allowed protocols caused the tests to run very slow with block unknown protocols disabled. Also required an update to flash part the way through the test.
Ian
All I know is that if I have the IPS enable
And this as the only rule with IPS enable
my CPU while doing a https not managed by that rule download at 30MB/s look like this, (CPU5 and 7 are not attached to Sophos XG)
As far as I know this traffic shouldn't be analyzed by Sophos XG because the rule managing this traffic doesn't have IPS enable.
Then if I disable the IPS Service
under the same conditions my CPU utilization is:
So obviously the IPS is analysing traffic that it should not analyze, and this is a bad implementation of Snort, this https traffic should go through the firewall without and the IPS should not penalized the firewall performance.
I'm pretty sure this is a bug, could you bring this to sophos XG engineers to study it and fix it?
In other firewalls the IPS only works if the rule associated to the IPS is managing traffic, in Sophos XG is not the case.
Now I have disable DoS settings
And again under the same conditions the CPU load seems to be similar
My rules
IPS service disable and DoS settings disable:
I have replicated the test, this time with speedtest.
IPS engine Enable DoS Disable
IPS engine Disable DoS Disable
I have replicated the test, this time with speedtest.
IPS engine Enable DoS Disable
IPS engine Disable DoS Disable