Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Snort takes too heavy process at Bridge Mode (Not used IPS in any rule)

Snort takes too heavy process at Bridge Mode (Not used IPS in any rule).

It communicate of clients delayed & lose that under the Sophos appliance.

Check please.

HW Appliance SG105 ~ SG135

v16.01.1 ~ v16.01.2



This thread was automatically locked due to age.
Parents Reply
  • Oh by the way - I did the fixes earlier in the thread which didn't help:

    set ips maxpkts 8

    console> system application_classification off
    Microapp discovery is also turned off because it is dependent on this feature.

     

    However, I'll add on 'maxsesbytes 8192' as a further test

Children