Sophos Community
Sophos Community
  • User
  • Site
  • Search
  • User
  • Community & Product Forums
  • Blogs
  • Partners
  • Events & Webinars
  • Getting Started
  • Support Portal
  • Community Blogs
    • Application Control
    • Community
    • Product documentation
    • Security
  • Feedback
    • Support Portal
    • Product documentation
  • Products
    • Endpoint security
      • Sophos Endpoint
      • Sophos XDR
      • Device Encryption
      • Sophos Mobile
    • Network Security
      • Sophos Firewall
      • Sophos ZTNA
      • Sophos Switch
      • UTM Firewall
      • Sophos Wireless
      • Sophos NDR
    • Email Security
      • Sophos Email
      • Phish Threat
    • Cloud Security
      • Sophos Central
      • Sophos Cloud Optix
    • Support Tools
      • Sophos integrations
      • Free tools
    • AI Solutions
      • Sophos AI
  • Services
    • Management platform
      • Sophos Professional Services
      • Sophos Central
      • Support Portal
      • Sophos Community log in
  • Sophos Partners
    • Partners blog
    • Local Partner community
    • Partner news
  • Resources
    • MSP guides
    • Partner Care
    • Sophos Central
  • Webinars & Events
    • Webinars & Events
    • Calendar
  • Become a partner
    • Join our program
  • Events & Webinars
    • Events & Webinars
    • Calendar
    • Recordings
  • Getting started in the Community
    • How to get started
    • SophosID registration
    • How to set up your profile
    • How to contribute and participate
    • How to manage private messages
  • Member recognition
    • Recognition program
    • Leaderboard
  • Products and Services
    • Products
      • Endpoint security
        • Sophos Endpoint
        • Sophos XDR
        • Device Encryption
        • Sophos Mobile
      • Network Security
        • Sophos Firewall
        • ZTNA
        • Sophos Switch
        • UTM Firewall
        • Sophos Wireless
        • NDR
      • Email Security
        • Sophos Email
        • Phish Threat
      • Cloud Security
        • Sophos Central
        • Sophos Cloud Optix
      • Support Tools
        • Sophos integrations
        • Free tools
      • AI Solutions
        • Sophos AI
    • Services
      • Management platform
        • Sophos Professional Services
        • Sophos Central
        • Support Portal
        • Sophos Community log in
  • Blogs
    • Community Blogs
      • Application Control
      • Community
      • Product documentation
      • Security
    • Feedback
      • Support Portal
      • Product documentation
  • Partners
    • Sophos Partners
      • Partners blog
      • Local Partner community
      • Partner news
    • Resources
      • MSP guides
      • Partner Care
      • Sophos Central
    • Webinars & Events
      • Webinars & Events
      • Calendar
    • Become a partner
      • Join our program
  • Events & Webinars
    • Events & Webinars
      • Events & Webinars
      • Calendar
      • Recordings
  • Getting Started
    • Getting started in the Community
      • How to get started
      • SophosID registration
      • How to set up your profile
      • How to contribute and participate
      • How to manage private messages
    • Member recognition
      • Recognition program
      • Leaderboard
  • Support Portal
Sophos Firewall
Sophos Firewall
Discussions Sophos Firewall: v19.0 MR1: Feedback and experiences
  • Release Notes & News
  • Discussions
  • Recommended Reads
  • Early Access Programs
  • More
  • Cancel
  • New
Sophos Firewall requires membership for participation - click to join
Thread Info
  • State Verified Answer
  • +1 person also asked this people also asked this
  • Locked Locked
  • Replies 242 replies
  • Answers 6 answers
  • Subscribers 68 subscribers
  • Views 35986 views
  • Users 0 members are here
  • Sophos Firewall
  • v19.0 MR1
Options
  • RSS
  • More
  • Cancel
Suggested
This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Sophos Firewall: v19.0 MR1: Feedback and experiences

LuCar Toni
LuCar Toni over 3 years ago

Re-Release: https://community.sophos.com/sophos-xg-firewall/b/blog/posts/sophos-firewall-v19-mr1-re_2d00_release-build-365-is-now-available

https://community.sophos.com/sophos-xg-firewall/b/blog/posts/sophos-firewall-v19-mr1-is-now-available

Release Notes: https://docs.sophos.com/releasenotes/output/en-us/nsg/sf_190_rn.html

"Old" V18.5 MR4 Thread: https://community.sophos.com/sophos-xg-firewall/f/discussions/134965/sophos-firewall-v18-5-mr4-feedback-and-experiences

V19.0 GA Thread: https://community.sophos.com/sophos-xg-firewall/f/discussions/134009/sophos-firewall-v19-0-ga-feedback-and-experiences



This thread was automatically locked due to age.
  • Cancel

Top Replies

  • LuCar Toni
    LuCar Toni over 3 years ago in reply to EdmundSackbauer +4
    NEW KIL entry:
  • shred
    0 shred over 3 years ago in reply to LuCar Toni

    It looks like there was a sudden jump in memory usage. top is showing snort processes consuming the most currently.

    • Cancel
    • Vote Up 0 Vote Down
    • Cancel
  • LuCar Toni
    0 LuCar Toni over 3 years ago in reply to shred

    Does any of those time values match with the sudden increase of the RAM? 

    You see the run time and the increase seems to be some hours ago. Which process matches? 

    • Cancel
    • Vote Up 0 Vote Down
    • Cancel
  • shred
    0 shred over 3 years ago in reply to LuCar Toni

    Looking at the memory usage graph, it appears the increase in memory was at 3:34 AM local time. It was around 9:00 AM local time when I looked at top, so about 5 hours and 30 minutes from the increase in memory usage. It looks like it was an increase of 1,437 MB and I none of the times in top seem to correspond to an increase around that time (just looking at what appears to be the uptime for each process in top). 

    I’ll keep letting it run for now to see what happens but I’ll reboot at some point if nothing changes and try to get some before and after screenshots.

    • Cancel
    • Vote Up 0 Vote Down
    • Cancel
  • alda
    0 alda over 3 years ago in reply to shred

    Hello shred,

    I have exactly the same experience on my virtual app. For a long time, the RAM memory is at about 50%, but now it is at 89%. But according to the RAM load graph, the spike didn't come until midday today. Probably a bad snort engine update?

    Regards

    alda

    • Cancel
    • Vote Up 0 Vote Down
    • Cancel
  • shred
    0 shred over 3 years ago in reply to alda

    Ah that’s a good point on updates. Looking at mine, it looks like my IPS signatures haven’t been updated since 28 Jul but my AV and ATP was updated at 03:29:01, Aug 01 2022 which corresponds closely to the big jump in memory usage.

    • Cancel
    • Vote Up 0 Vote Down
    • Cancel
  • LuCar Toni
    0 LuCar Toni over 3 years ago in reply to shred

    You can give me a Support Access ID and i will forward this for further inspection. 

    • Cancel
    • Vote Up 0 Vote Down
    • Cancel
  • shred
    0 shred over 3 years ago in reply to LuCar Toni

    Sent you a message with the Access ID. Also, I can see my memory use has increased to 91% and checking top, it’s definitely the snort processes increasing in memory usage.

    • Cancel
    • Vote Up 0 Vote Down
    • Cancel
  • rfcat_vk
    0 rfcat_vk over 3 years ago in reply to shred

    Avira and ATP came through at the same time and memory use has grown.

    Ian

    • Cancel
    • Vote Up 0 Vote Down
    • Cancel
  • LuCar Toni
    0 LuCar Toni over 3 years ago in reply to rfcat_vk

    Just to wrap up: 

    NC-100681

    Increase in snort memory with ATP pattern updates

    • Cancel
    • Vote Up +2 Vote Down
    • Cancel
  • MarekDalke
    0 MarekDalke over 3 years ago in reply to MarekDalke

    Temporary workaround provided by Support Engineer which I believe I can share here.

    You need to modify the timer value in /sys/class/net/<affected_interface_name>/bridge/ageing_time from 0 to 30000. In my case:

    # echo 30000 > /sys/class/net/wlnet3/bridge/ageing_time

    After above modification traffic started to hit the firewall rule as before the upgrade to v19.0.1 MR-1.

    • Cancel
    • Vote Up +3 Vote Down
    • Cancel
<>

Defeat Cyberattacks

Footer - Default

  • Column 1
    • Endpoint Security
      • Sophos Endpoint
      • Sophos XDR
      • Device Encryption
      • Sophos Mobile
    • Email Security
      • Sophos Email
      • Phish Threat
    • Support Tools
      • Sophos integrations
      • Free tools
  • Column 2
    • Network Security
      • Sophos Firewall
      • Sophos ZTNA
      • Sophos Switch
      • UTM Firewall
      • Sophos Wireless
      • Sophos NDR
    • Cloud Security
      • Sophos Central
      • Sophos Cloud Optix
  • Column 3
    • Partners
      • Find a partner
      • Managed service providers
      • Join our program
    • Current Partners
      • Partners blog
      • Local Partner Community blog
      • Partner MSG guides
      • Partner news
      • Partner care
      • Partner portal login
      • Training & certification
    • Management Platform
      • Sophos Central
  • Column 4
    • Support
      • Downloads and updates
      • Support packages
      • Support portal
      • Sophos Customer Success
      • Sophos Techvids
      • Sophos Learning Center
      • Sophos status
      • Tech support
    • Learn
      • Threat intelligence
      • X-Ops threat research
      • Trust center
      • Security blogs
      • Sophos Academy
  • Column 5
    • Getting Started
      • How to get started
      • Community FAQs
    • Member Recognition
      • Recognition program
      • Leaderboard
    • Events & Webinars
      • Webinars
      • Calendar
      • Recordings
  • Column 6
    • Try for Free
      • Free trials
      • Product demos
    • Sophos Home Premium
      • Sophos Home support
      • Contact Home support
      • Mac antivirus download
      • PC antivirus download
    • About Us
      • Company
      • Events
      • Press
      • Careers
  • Getting Started
  • Terms
  • Privacy
    • Privacy Notice
    • Cookies
  • Legal
    • General
    • Modern Slavery Statement
    • Speak Out
© 1997- Sophos Ltd. All Rights Reserved.