Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Troubleshooting high WAN BW usage

Hello,

i'm having an issue in a customer deploy that the wan is showing CONSTANT very high usage, but the corresponding LAN traffic is not there.

if i open the flow monitor on the WAN port, i see that application HTTP is consuming all the BW with 3 clients, when i click the client it shows the PUBLIC IP address of the WAN port as the offending culprit.(~800KBPS/8mbits of download traffic)

But if i open the flow monitor for the LAN port i have less than 1mbit of traffic either direction.

i have no PF rules or internal web servers, in fact there are NO port forwards open.

¿how do i troubleshoot this?, the PF livelog is not showing any blocked traffic on http port.

Web filtering is active with AV scan, could this be files being downloaded by the proxy(but it's happening throughout the entire workday!) before the utm allowing the download?, but i have a 30MB file limit set...

i also don't see anyway to monitor what current files are being downloaded by the web proxy.

 

edit: i even blocked HTTP from the flow control, which created an app control rule... well, it's not working!, it's not blocking anything and traffic still is maxed out



This thread was automatically locked due to age.
Parents
  • This sounds like httpproxy is trying to download a file, but the download is continually interrupted and restarted.  What happens if you disable/enable Web Filtering?

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
  • also, this happoened with a new SG unit that replaced an old UTM220, with the utm220 backup restored to it.

    so same config, with sg unit it started working badly.

     

    i've disabled http proxy and the issue persists(i haven't been able to trace the usage after disabling it today)

Reply
  • also, this happoened with a new SG unit that replaced an old UTM220, with the utm220 backup restored to it.

    so same config, with sg unit it started working badly.

     

    i've disabled http proxy and the issue persists(i haven't been able to trace the usage after disabling it today)

Children
No Data
Share Feedback
×

Submitted a Tech Support Case lately from the Support Portal?