Is it possible to get the hardware limitations removed for the home version? Or have they been removed in V18?
This thread was automatically locked due to age.
Is it possible to get the hardware limitations removed for the home version? Or have they been removed in V18?
C'mon mate, lets imagine that sophos has to pay salaries, developing new solutions, ideas maintain current activities, infrastructure etc etc. We can be glad that sophos is allowing us a home users to using their product just for free with all features. Beside that, for home usage 4 cores and 6 gb is a overkill. With all features on you can gain 1GB/s. look how Fortigate(and other solutions) are expensive, what the are offering etc. With sophos you've got it for free with great community :) appreciate it ^^ and if you wanna use it for commercial just support it - buying it ;)
I understand this logic, but there is no reason to limit hardware if it is proven that the UTM is in a home location. There are tons of other UTM packages out there that don't have hardware limitations. I don't mind paying the annual license, but to pay the annual license with a hardware restriction is weak. I guess I'll just stay on PFsense until they finally decide to remove the limitations. Thanks
console> system firewall-acceleration show
Firewall Acceleration is Disabled. Fastpath Unload Failed.
This topic was recently discussed here: community.sophos.com/.../questions-about-the-fastpath-feature
FW accel and Fastpath should be disabled for not-ESX hypervisors, see here: https://docs.sophos.com/nsg/sophos-firewall/18.0/Help/en-us/webhelp/onlinehelp/nsg/sfos/concepts/Architecture.html
Any news above increase the CPU or RAM limit? CPU is particulary a problem in virtualized environments.
Can something be done in this regard?
I can't compare vs a non virualized environment but I know the HW that some Sophos XG appliaces has and the cores of my CPU should be much more powerfull despite being virtualized.
www.amd.com/.../amd-ryzen-5-2400g
At least I can tell you that the overhead per core due to virtualization is around 10% in my case, comparing htop in host and on VM.
NIC are passthough and everyhing from a KVM perspective (CPU, Storage is in raw format) is optimiced to increase performance.
I have assigned 6gb DRR4 at 3000MHz
NVME samsung evo 970 dedicated
I have 600mpbs symetric
If I enable IPS and APPs, it depens but download is around 300 and upload 170 or so.
The thing is that even with a light configuration CPU cores reach 100%. My area will move soon to 1Gbps, so probably I will have problems. I can get a better CPU but that won't help a lot since more than 4 cores can't be assigned and my CPU can reach 3.8Ghz boost to is a lot more compared with atoms and celerons which are usually around 2.5Ghz.
I know that part of the issue is snort but snort will move soon to snort 3 and will work much better with muilticore like suricata. Another thing is how many years will take sophos to implement snort 3 once released.
Ram is usually around 4gb.
I can't see how you're hitting 100% CPU - I was running Sophos G on a Dell Optiplex 3010 with i5-3470, HP 2x port 1Gb card, and the machine had 8GB RAM, 128GB SSD, the CPU with the 500/35 VM Connection here never went about 18%, that was running v18 with IPS, DPI, Web policies, Application policies.
Something is either wrong with your configuration, or the AMD processors just can't and don't perform well - I've seen issues in the past with pfSense and AMD - hence the reason I'm suggesting this as a possibility.
I can't see how you're hitting 100% CPU - I was running Sophos G on a Dell Optiplex 3010 with i5-3470, HP 2x port 1Gb card, and the machine had 8GB RAM, 128GB SSD, the CPU with the 500/35 VM Connection here never went about 18%, that was running v18 with IPS, DPI, Web policies, Application policies.
Something is either wrong with your configuration, or the AMD processors just can't and don't perform well - I've seen issues in the past with pfSense and AMD - hence the reason I'm suggesting this as a possibility.