Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

IPS performance issues after ugprade to SFOS 16.05.4 MR4

Hi together,

I'm experiencing a strange issue since the upgrade from SFOS 16.05.3 MR3 to SFOS 16.05.4 MR4:

I've created several specific IPS policies to optimize the performance for each FW rule. E.g. I'm using a LAN-to-WAN policy with ~1400 patterns for my non-Windows clients.

The performance with MR3 was great and I could easily reach 100mbit/s download speeds while snort used up to 70% of a single core cpu. (XG was much faster than UTM 9 on the same hardware at this time!)

 

However after the upgrade to MR4 the performance dropped to 60mbit/s download while the snort process goes up to 100% cpu core utilization.

I started to experiment with my IPS policies and found out that the count of patterns within a policy doesn't seem to affect this behaviour at all.

It doesn't matter if the policy has a total of 3 patterns or over 8000 when selecting everything. The poor performance is present with the first pattern.

The only way to get back the full speed is to choose no IPS policy for this firewall rule.

 

It would be great if someone could help me with this issue. :-)

 

Thanks and best regards

DomNik



This thread was automatically locked due to age.
Parents
  • DomNik,

    check the ips-settings from CLI:

    show ips-settings

    and post the result.  Maybe the configuration was different on MR3.

    Regards

  • Hi lferrara,

    thanks for your reply.

    This is the output - I think the settings should be correct:

    console> show ips-settings

    -------------IPS Settings-------------

    stream on

    lowmem off

    maxsesbytes 0

    maxpkts 8

    enable_appsignatures on

    http_response_scan_limit  65535

    search_method ac-q

    sip_preproc enabled

    sip_ignore_call_channel enabled

     

    -------------IPS Instances------------

    IPS CPU

     1  0

     2  1

     

    console> show ips_conf 

    config stream 1

    config stdsig 1

    config qnum 10

    config maxpkts 8

    config disable_tcpopt_experimental_drops 0

    config enable_appsignatures 1

    config failclose off

    config cpulist 0:1

    var SEARCH_METHOD ac-q

    var SIP_STATUS enabled

    var IGNORE_CALL_CHANNEL enabled

    config maxsesbytes 0

     

    Greets

    DomNik

  • DomNik,

    if you can, compare the settings by rolling-back to MR3. It is strange that performance are degraded.

    Thanks

  • Speed is back after upgrading to MR5 and IPS pattern version 3.13.65.

    Problem solved. :-)

Reply Children
No Data