After upgrading to 9.306, all users of all interfaces (VLANs) are experiencing very slow response.
We are using Hot-Standby mode
This thread was automatically locked due to age.
Barry,
It was logging UDP-4500 flood for the NAT-VPN, but this is not correct since our Cisco IPS was not seeing it.
Thanks for checking. No update from Sophos
The "UDP-4500 flood" was a valid NAT-IPsec request from a VPN peer.
So current state as follows:
1. Global IPS enabled, the rest are disabled: TCP/UDP/ICMP DoS and Anti-Portscan disabled, Pattern disabled.
2. Threat Detection enabled.
3. Antivirus and Anti-Spyware disabled.
4. Hot-Standby
5. Several Parent Proxies connected using IPSec VPN tunnels.
6. Several Web Filter Profiles pointing to unique Parent Proxy, and block personnal emails (Gmail, Hotmail, etc.)
7. Several interfaces (Vlans/Subnets) for wired clients.
8. CPU= 2%, Memory=10%
9. Users= 5 (designed for many-many users).
Performance:
download= normal at about 50-mbps
upload= half normal about 25-mbps
thanks...
William,
Yes you are right, practically my IPS is off (only using antivirus). No DoS protection.
As for hardware, he have abundant one: mega CPU, RAM, Disk. I can assure it is not HW.
We have Vyatta performing heavier function, and the CPU is in 2%. If Vyatta has SSO username logging, we would not go for UTM. Vyatta is very stable and cheaper.
Thanks,
Audie