Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Home XG 18 MR4 - Incorrect usage reported for sessions over 4GB

Hi

I have noticed weird logging and reporting behavior on the XG when transfering more than 4GB during one connection session.

I tried to reboot the firewall, but no difference. You can see results of some of my tests below. Reports and policy counters were clean before the tests.

After transfering 1GB file the session is logged correctly in log viewer. See sent bytes in image below:

/resized-image/__size/1900x111/__key/communityserver-discussions-components-files/126/1G_5F00_file_5F00_log_5F00_viewer.JPG

After transfering 3GB file in new session (remount of cifs share) its also logged correctly in log viewer. See sent bytes in image below:

/resized-image/__size/1891x480/__key/communityserver-discussions-components-files/126/3G_5F00_file_5F00_log_5F00_viewer.JPG

But after transfering 5GB file in new session (remount of cifs share) its logged wrong. See sent bytes in image below. Its only shows around 1GB of data (does the counter overflow on 4GB?):

/resized-image/__size/1874x480/__key/communityserver-discussions-components-files/126/5G_5F00_file_5F00_log_5F00_viewer.JPG

When checking the session in live connections, before I umounted the NAS it was showing correct amount of data. See upload transfer on image below:

/resized-image/__size/1100x480/__key/communityserver-discussions-components-files/126/5G_5F00_file_5F00_live_5F00_connection.JPG

Also the firewall policy counter shouws correct ammount of total data that I transfered during this testing (1GB+3GB+5GB = 9GB). See out on image below:

/resized-image/__size/1055x480/__key/communityserver-discussions-components-files/126/total_5F00_policy_5F00_counter.JPG

Reports also show wrong data. It shows only 5GB total. That corresponds with what I saw in log viewer, where the last 5GB session was logged as 1GB only. See report image below:

/resized-image/__size/545x480/__key/communityserver-discussions-components-files/126/total_5F00_report.JPG

What is also bugging me is that sophos XG logs and reports sessions only after they end. That is probably a feature and not a bug, but its very wrong in my opinion. I have for example NFS sessions that are up for 30 days between two servers (reboot only during monthly update cycle) and its not reported or logged anywhere in the XG. I can see it between live connections, but its not in the reports until I actualy remount the NFS (session is closed and new one is created). I would much more prefere a behavior that I see for example on fortinet fortigate firewalls, where it works like described below:

"Each ongoing session generates a statistic log every two minutes, starting two minutes after the session was established. This means a session can generate multiple logs over its lifetime.
After the session is closed, a final log with overall stats will be generated
"

Am I missing something here? Can somebody confirm this behavior? So far I am not very pleased by the sophos XG logging and reporting. Unless I am doing something horribly wrong I think that it needs a lot of improvements....

I am currently testing sophos XG 18 MR4 on VM with 1CPU and 4GB of RAM. Its home license.



This thread was automatically locked due to age.
Parents
  • Welcome to XG and it’s very poor logging performance.

    we the forum members are hoping there will be some major fixes to XG reporting when the mythical v18.5.x is released.

    you have only touched on the tip of reporting issues.

    ian

Reply
  • Welcome to XG and it’s very poor logging performance.

    we the forum members are hoping there will be some major fixes to XG reporting when the mythical v18.5.x is released.

    you have only touched on the tip of reporting issues.

    ian

Children
  • That is what I was afraid of... I am quite happy so far with other functionality on the XG, but the logging and reporting is like from some afla version product, compared to other firewalls that I worked with.

    Is there some roadmap or expected release date for v18.5?