Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Internet traffic stops every time XG has an IPS or ATP update

We have an issue with an XG-125 running MR3. Every time it does an ATP or IPS update, it blocks all traffic for two minutes.

Any suggestions would be welcome, I have opened a tech support case (03253973) with 'High' priority five days ago but haven't had a single response yet.



This thread was automatically locked due to age.
Parents
  • I've looked into this further but it doesn't seem to be limited to that one site. I checked our own site and that dropped all traffic for about 40s during an ATP update (I presume it was for a shorter period because it is an XG 230 and the update would have completed quicker).

  • Hi ,

    After a talk with the support, I've found out anything that makes the IPS (Snort) service restarts will make your firewall drop packets.

    Well, I've been facing a issue where creating a custom IPS signature, Snort would restart bringing a lot of packets down with it, after a while I've saw the same thing happens over IPS/ATP updates. This issue is a lot more noticeable on low-end CPUs since It takes a while to restart Snort.

    In v17.5 It would primarily drop only the traffic that had IPS within a policy, now on v18 It's even worse because if your doing TLS Decryption half of the decrypted traffic gets dropped and you have to refresh the entire page over the browser.

    The answer by them has - some traffic will get dropped while restarting Snort, so they will add this information at the Docs.

    Thanks!

Reply
  • Hi ,

    After a talk with the support, I've found out anything that makes the IPS (Snort) service restarts will make your firewall drop packets.

    Well, I've been facing a issue where creating a custom IPS signature, Snort would restart bringing a lot of packets down with it, after a while I've saw the same thing happens over IPS/ATP updates. This issue is a lot more noticeable on low-end CPUs since It takes a while to restart Snort.

    In v17.5 It would primarily drop only the traffic that had IPS within a policy, now on v18 It's even worse because if your doing TLS Decryption half of the decrypted traffic gets dropped and you have to refresh the entire page over the browser.

    The answer by them has - some traffic will get dropped while restarting Snort, so they will add this information at the Docs.

    Thanks!

Children