Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

SFOS 16.01.2 snort high cpu even with None in policy

Not sure if this is related to 16.01.2, or some pattern update, but shortly after I updated on 11/29 my CPU usage has more than doubled with no changes to configuration other than the 16.01.2 update (and probably some behind-the-scenes pattern updates).

 

 

I didn't even know the CPU was under load until the effects yesterday 12/7 when my traffic was screeching slow. When I logged onto the console snort was taking 100% CPU!

I checked a few links from the board and found my maxpxts was 80 so I adjusted that to 8 which has helped a lot keeping snort to around 60-70% CPU but the system is definitely running hotter than usual (compare to the previous SFOS 16.01.1).

It also seems like vlan routing (zone-to-zone) policies influence snort (some sort of pre-filtering?) even though IPS policy for that rule is set to None. Is there a way to exclude pre-filter snort traffic if the rule defines it as none?

Thanks



This thread was automatically locked due to age.
Parents
  • I have the same issue, and open case already.

    Stop IPS service can resolve the issus.

    But what should I do when user want to enable IPS function on some firewall rules?

    I am waiting for Sophos response...

  • Dear All,

    After support team working for two months, they resolved the issue of mine finally.

    They add a command 'set ips ips-instance add IPS cpu 1'.
     
    The command basically creates 2 instances of IPS, allowing the IPS to use the 2nd core of the appliance for processing of IPS traffic.

    And I also found that the snort procedure doesn't appear in CPU utility.

    Support team reply as following.

    Ans-> There can be multiple reason why the snort is not listed on the CPU utility, but at the same time, if it is not listed doesn't mean there is any problem.

     

    The issue resolved finally...

Reply
  • Dear All,

    After support team working for two months, they resolved the issue of mine finally.

    They add a command 'set ips ips-instance add IPS cpu 1'.
     
    The command basically creates 2 instances of IPS, allowing the IPS to use the 2nd core of the appliance for processing of IPS traffic.

    And I also found that the snort procedure doesn't appear in CPU utility.

    Support team reply as following.

    Ans-> There can be multiple reason why the snort is not listed on the CPU utility, but at the same time, if it is not listed doesn't mean there is any problem.

     

    The issue resolved finally...

Children