Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

UTM 9 - IPS tweaking?

Is there any recommendations for tweak IPS on a SG125w running UTM 9 (latest version)?

We have a 100Mb/sec LOS connection which drops from 100Mbps to 70Mbps with IPS enabled. 



This thread was automatically locked due to age.
Parents
  • I also see this in my IPS log, not sure what what the warning means?

    022:10:21-11:47:50 3gmanu-fw01 snort[2542]: | DFA
    2022:10:21-11:47:50 3gmanu-fw01 snort[2542]: | 1 byte states : 2.94
    2022:10:21-11:47:50 3gmanu-fw01 snort[2542]: | 2 byte states : 16.13
    2022:10:21-11:47:50 3gmanu-fw01 snort[2542]: | 4 byte states : 0.00
    2022:10:21-11:47:50 3gmanu-fw01 snort[2542]: +----------------------------------------------------------------
    2022:10:21-11:47:50 3gmanu-fw01 snort[2542]: WARNING: normalizations disabled because DAQ can't replace packets.
    2022:10:21-11:47:50 3gmanu-fw01 snort[2542]: Session Reload: Reference Count Non-zero for old configuration.
  • With IPS enabled, you will get a bit lower speed.  That's the nature of filtering, and with Sophos not updating Snort to a multi-threading capable version, it won't get any better unless IPS is disabled unfortunately.  XG may be different in handling this, and I'm sure it is, but... I don't use that product.

    WARNING: normalizations disabled because DAQ can't replace packets.

    That's a Snort warning, but it can be ignored for the most part, I believe.

Reply
  • With IPS enabled, you will get a bit lower speed.  That's the nature of filtering, and with Sophos not updating Snort to a multi-threading capable version, it won't get any better unless IPS is disabled unfortunately.  XG may be different in handling this, and I'm sure it is, but... I don't use that product.

    WARNING: normalizations disabled because DAQ can't replace packets.

    That's a Snort warning, but it can be ignored for the most part, I believe.

Children