Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

SFOS 16.01.2 snort high cpu even with None in policy

Not sure if this is related to 16.01.2, or some pattern update, but shortly after I updated on 11/29 my CPU usage has more than doubled with no changes to configuration other than the 16.01.2 update (and probably some behind-the-scenes pattern updates).

 

 

I didn't even know the CPU was under load until the effects yesterday 12/7 when my traffic was screeching slow. When I logged onto the console snort was taking 100% CPU!

I checked a few links from the board and found my maxpxts was 80 so I adjusted that to 8 which has helped a lot keeping snort to around 60-70% CPU but the system is definitely running hotter than usual (compare to the previous SFOS 16.01.1).

It also seems like vlan routing (zone-to-zone) policies influence snort (some sort of pre-filtering?) even though IPS policy for that rule is set to None. Is there a way to exclude pre-filter snort traffic if the rule defines it as none?

Thanks



This thread was automatically locked due to age.
Parents
  • Aside from the higher than usual CPU, I'm able to reproduce MAX snort CPU usage when moving data between vlan (zone-to-zone) even when IPS policy is set to None. I did some digging on the snort forums and there is a white_list.rules file where networks or IPs can be added to (trust) and skip the pre-filter processing. However when I try to edit the file the filesystem reports read only. Does anyone know how I can edit this file or where the option might be in the GUI (if it is)? Thanks

Reply
  • Aside from the higher than usual CPU, I'm able to reproduce MAX snort CPU usage when moving data between vlan (zone-to-zone) even when IPS policy is set to None. I did some digging on the snort forums and there is a white_list.rules file where networks or IPs can be added to (trust) and skip the pre-filter processing. However when I try to edit the file the filesystem reports read only. Does anyone know how I can edit this file or where the option might be in the GUI (if it is)? Thanks

Children
No Data