This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

SFOS 16.01.0 known IPS issue - Work arounds?

Hey all,

Anyone have any other work around for the known IPS issue (NC-8238   [IPS] IPS Service drops legitimate traffic in very high load average conditions)? The IPS service seems to constantly fail to start and causes this issue from what I can see (CPU usage and memory usage spike all over the place). As my work around, I set the IPS service to Stop, performance and traffic return to normal. Obviously this isn't a great solution... Anyone have anything better? 

I'd like to know when this will be resolved too, seems to me to be a rather big problem. I may actually just roll back to 15 if this is going to be a thing for a while.

Thanks !!



This thread was automatically locked due to age.
  • I finally got around to shifting some stuff and freed up a "new" PC for the XG. 

    IPS is now working 100%, on a Core2Quad Q6600 with only 2GB RAM. This confirms that anything of the Athlon64 X2 or Pentium D/ P4 era will not be able to handle XG with IPS running. Core2 or newer should be a listed minimum requirement. 

  • Aditya Patel said:

    HI All

    I may have a Work aournd  by changing the IPS settings , As this is a Workaround

    Default IPS settings

    stream on
    lowmem off
    maxsesbytes 0
    maxpkts 100
    enable_appsignatures on
    http_response_scan_limit 65535

    Run Commands on Console 

    set ips maxsesbytes-settings update 8192
    set ips maxpkts 8

    IPS settings after changes 

    -------------IPS Settings-------------
    stream on
    lowmem off
    maxsesbytes 8192
    maxpkts 8
    enable_appsignatures on
    http_response_scan_limit 65535

     This should help..

     

     

    Hi Aditya,

     

    this also worked for 17.5.10 MR 10 with an I7 from Qotom. This happened after Updating my Internet Connection to Gbit (before 200Mbit)

     

    Thank you so much. Even this is old i thought it might be helpful to others

     

    Regards

    crash9877