Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Schedule pattern updates at a specific time

Hi, 

I am having issues with pattern updates on a XG210 HA cluster. Every time it does IPS and AV updates, connections get dropped. The only way I found for it not to impact the users is to have it do pattern updates at night only. However, in order to have this happen you have to set the auto update interval to Daily, then disable and reenable auto update AT THE EXACT TIME YOU WANT IT TO HAPPEN! Which means that if I want to have the pattern updates at 3am, I have to do this config at 3am. Oh, and of course every time the firewall reboots or there is a failover, the pattern update time is reset back to when the reboot / failover happened. So you have to do the config again, at 3am. Every time. Obviously highly inconvenient and ridiculous. Is there any way to schedule pattern updates at a specific time? If not, can you please implement that, or even better, fix the connection drop issue while IPS / AV pattern updates happen? 

Thanks

Nathalie Lambert



This thread was automatically locked due to age.
Parents Reply Children
  • I showed that article to all our Sophos XG devices and they just shrugged!

    We manage 3 100 series devices that all run with a memory utilisation of 60-70%. They all drop traffic for 2-3 minutes when there is a IPS/ATP update. Whatever the reason, this is unacceptable. This is not just my opinion, it is the opinion of Sophos's own technical support. You may say that that isn't enough memory free but these are all new XGs so Sophos should supply hardware with more memory or at least provide a workaround by allowing us to schedule those updates.

    I appreciate this isn't necessarily relevant to the OP as they have a 210. I need to check this on our own 230. I know on my home XG (a rev1 430) it drops traffic for 4 seconds (it's running home edition but is only running at 35% memory utilisation), so the claim "IPS engine is reconfigured without any interruption" is still not true (this was tested on MR3 or 4, it's a few months ago and I can't remember what was current at the time).

    I have tested this extensively with a program called Pingplotter that constantly monitors connectivity. I can then check the timing of service interruption against the update times. I have had a support case escalated to a senior level but the answer from the development team is just "that's the way it works". I wasn't aware of this article at the time but I'm sure if I pointed it out to them they would just change the article!