Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Snort takes too heavy process at Bridge Mode (Not used IPS in any rule)

Snort takes too heavy process at Bridge Mode (Not used IPS in any rule).

It communicate of clients delayed & lose that under the Sophos appliance.

Check please.

HW Appliance SG105 ~ SG135

v16.01.1 ~ v16.01.2



This thread was automatically locked due to age.
Parents Reply
  • Case is open. screenshot attached.

    But Sophos support engineer does not provide any help. Just keep calm.

    Anyway, Solved without Sophos support.

    There are two resolutions

    1. Disable application classificataion
      console> system application_classification off
    2. Change maxpkts value. Default is 80.
      console> set ips maxpkts (low number, likely 1/10 level)
Children