Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Any idea why an XG would download 2Mbps for 9 days straight?

I have no idea why but the XG i have (that is in transparent bridge mode) was downloading 2Mbps straight for 9 days.

It wasn't doing this on behalf of any host on my network, the traffic did not show up in the XG dashboard.  It only showed up on my edge router and the comcast bandwidth CAP that i hit :-( - once i unplugged the box out of the path the downloads stopped.

Before i plugged it back in I wondered if anyone had pointers on what to look at on the box, i assume i would need to do it in the Linux SSH console but not sure where to start to find out what process it was etc.

 

alex



This thread was automatically locked due to age.
Parents
  • Hi Alex, 

    Could you check live connections or the current connections in your XG. Make sure no system is connected to you may get appropriate results. 

    console> system diagnostics utilities connections v4 show

    you may also check the bandwidth monitor which is almost realtime . 

    console> system diagnostics utilities bandwidth-monitor

  • Thanks, definitely checked connections and reports - nothing, the XG insisted it had downloaded about 30GB on behalf of the listed hosts (and broke that out on  a per host basis) and the comcast and router showed it closer to 800GB.

    I didn't check the system diagnostics will do that and report back, hopefully it was transient issue...

    .. i was wondering if the XG might have been in an infinite downloading loop for maybe something like the signatures?  Would the bandwidth monitor show something like that?

  • Hi Alex, 

    Most of the updates from the XG device would contain AV , signature and pattern updates. It's possible that one of the updates has failed and retried again but the amount of traffic is minimal. 

    Could you check in any of the pattern updates has failed? Dashboard > Backup and Firmware > Pattern updates> Update Status. 

    You may also set the interval of the pattern update ranged from every 15 minutes  to 2 days

Reply
  • Hi Alex, 

    Most of the updates from the XG device would contain AV , signature and pattern updates. It's possible that one of the updates has failed and retried again but the amount of traffic is minimal. 

    Could you check in any of the pattern updates has failed? Dashboard > Backup and Firmware > Pattern updates> Update Status. 

    You may also set the interval of the pattern update ranged from every 15 minutes  to 2 days

Children
No Data