Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Snort takes too heavy process at Bridge Mode (Not used IPS in any rule)

Snort takes too heavy process at Bridge Mode (Not used IPS in any rule).

It communicate of clients delayed & lose that under the Sophos appliance.

Check please.

HW Appliance SG105 ~ SG135

v16.01.1 ~ v16.01.2



This thread was automatically locked due to age.
Parents Reply
  • HI All,

    I may have a Work aournd  by changing the IPS settings , 

    Default IPS settings

    stream on
    lowmem off
    maxsesbytes 0
    maxpkts 100
    enable_appsignatures on
    http_response_scan_limit 65535

    Run Commands on Console 

    set ips maxsesbytes-settings update 8192
    set ips maxpkts 8

    IPS settings after changes 

    -------------IPS Settings-------------
    stream on
    lowmem off
    maxsesbytes 8192
    maxpkts 8
    enable_appsignatures on
    http_response_scan_limit 65535

     This should help 

Children