Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

CPU load 99,9 % when activating Web Protection / awarrenhttp service

We have the following phenomenon / problem:

As soon as we activate a firewall rule that controls HTTP / HTTPS access (To top priority LAN to WAN) the web policy, the CPU load is constantly increased to 99.9 %.

As soon as we take out the filter, the load goes down again. The same applies to the malware scans, for example HTTP scan.

- 100 Kb/s - 500 Kbps maximum on the WAN interface
- in the web policy only one category is stored in the web policy
- The IPS settings are all active, but they do not affect the CPU load
- Malware scanning options are all disabled
- Pharming Protection is disabled
- tcp and udp flood is not activated
- it happens in 16.5.3 and also 16.5.7


In the awarrenhttp.log I often see the following message:

1505204736.496967459[15548/ (nil)] aptpscanner. c: 169 create_aptp_instance APTP unavailable
1505204736.497019971[15548/0x7f68fc414000] aptpscanner. c: 267 threat_scan APTP unavailable

As well as this one.

1505204846.928649047[15548/0x7f68fc414000] epoll. c: 1424 plain_write_vector Write error on the epoll handler 30 (Connection reset by peer)
1505204846.979740973[15548/0x7f68f971f971f000] epoll. c: 1424 plain_write_vector Write error on the epoll handler 41 (Connection reset by peer)

What setting options did I miss?


I've already seen this question, but I haven't found a helpful answer to it.

I am grateful for every tip ! Many thanks in advance.

Max



This thread was automatically locked due to age.
  • Max,

    can you give us details about the system spec of the HW you are using?

    Thanks

  • HI Luk,

     

    Appliance Model:                XG125
    Firmware Version:               SFOS 16.05.7 MR-7
    Firmware Build:                 305
    Firmware Loader version:        0x00000005
    HW version:                     XN02
    Config DB version:              16.510
    Signature DB version:           16.510
    Report DB version:              16.510
    Webcat Signature version:       0.0.1.233
    Web Proxy version:              HTTP-Proxy.09117acb5
    SMTP Proxy version:             1.0
    POP/IMAP Proxy version:         1.0.0.3.4
    Logging Daemon version:         0.0.0.17
    AP Firmware:                    9.0.001
    ATP:                            1.0.0159
    Avira AV:                       1.0.20564
    Authentication Clients:         1.0.0008
    IPS and Application signatures: 3.13.94
    RED Firmware:                   2.0.008
    Sophos AV:                      1.0.11490
    SSLVPN Clients:                 1.0.007
    WAF:                            1.0.0006
    Hot Fix version:                N.A

     

    Max

  • Thanks Max. Number of users, bandwidth?

  • max. 16 Users / Bandwidth: 50 000

    Max

  • So i have a workaround - when you disable the ATP subscription the web filter works again and the load goes off