This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

IPS - 17.5.7 MR-7

Like many people I have seen posting, I am having issues with slow performance with IPS enabled (policy bound to my firewall rule). I recently upgraded my hardware (now running on a Qotom - I7 / dual core) - should be more than adequate to hit 175Mbps!. Without the rule - I get 175Mbps - using several tests (i.e. speedtest.net and a test utility provided by Cox). When I apply the rule, I'm stuck at about 130Mbps. Overall CPU utilization never actually his over 50% on the firewall. I also have 6G of RAM - so memory isn't an issue (only have a few rules defined). 

I do have a custom rule I created which only targets categories and platforms I care about. However, as a test - I actually started deleted them incrementally - to the point where I finally ended up with an empty policy! And even with an empty policy applied - exact same results! As I incrementally removed signature groups, there was no change in performance whatsoever.

I have read all of the posts - I have all of the DOS features and spoof protection features disabled... 

Considering the behavior starts by simply applying the rule - and performance does't change irrespective of how many signatures are included  -  this doesn't seem like a CPU or hardware issue. The CPU is running at 2.7Ghz - and based on specs of higher end Sophos platforms, this should be more than adequate. And based on the way SNORT works, having more than 2 cores wouldn't make a difference either (and this is apparent since I am not seeing excessive CPU utilization on the firewall itself).

Are there any known issues with 17.5.7 MR-7 that could cause this? Any optimizations I can try? I verified the output of "show ips-settings" is consistent with what support said it should be - so not sure what console level changes are relevant. 

Any help appreciated. Thanks! 



This thread was automatically locked due to age.
Parents
  • I’m running Sophos XG MR-7 on a Qotom Q335G4 (Intel Core i5 w/ 4GB RAM). I’m able to achieve 300 Mbps down (max for my ISP plan) with IPS enabled and a fairly extensive ruleset. At my previous house I had a 1GB ISP plan and I remember being able to achieve 600+ Mbps with IPS enabled. As you mentioned, the number of signatures seem to have no impact on the throughput which I find odd. I didn’t change any settings with the Qotom device specifically other than disabling XHCI Mode in the BIOS so it would read my USB drive on boot and setting the power loss option to restart the device after a power loss.

    Here’s the output of ‘show ips-settings’:

    Sophos Firmware Version SFOS 17.5.7 MR-7

    console> show ips-settings

    -------------IPS Settings-------------

           stream on

           lowmem off

           maxsesbytes 0

           maxpkts 8

           enable_appsignatures on

           http_response_scan_limit  65535

           search_method ac-q

           sip_preproc enabled

           sip_ignore_call_channel enabled

    -------------IPS Instances------------

    IPS CPU

    1  0

    2  1

    3  2

    4  3

    Just a theory - have you checked your CPU temps? Only way I know how is in the BIOS but if you’re running pfSense, you should be able to see it there. I wonder if there’s perhaps an issue with how your heatsink is seated and maybe the CPU is throttling when under load?

    Also, I’m fairly certain you’ve checked this but did your ‘Total available WAN bandwidth’ some how get set to a value you didn’t intend? I suppose all of this doesn’t really matter since you’re on pfSense now but just posting this in case anyone else runs into similar issues.

  • I assume that Qotom is a dual core like mine (mine is I7 dual core). Why is yours showing 4 cpu cores:

    IPS CPU

    1  0

    2  1

    3  2

    4  3

     

    Mine only shows two. Are you running VMWARE (I am running Vsphere 6.7). If so, what are the CPU settings (CPUs / Sockets) ? Anyway, just curious.

     

  • Yeah, it's the Intel Core i5-5200U. Dual core but has Hyper-Threading hence the 4 apparent "cores". I'm assuming you have the Core i7-5500U so it should be the same (two cores with Hyper-Threading). I just have Sophos XG running directly on the Qotom.

Reply Children
No Data