After upgrading to 9.306, all users of all interfaces (VLANs) are experiencing very slow response.
We are using Hot-Standby mode
This thread was automatically locked due to age.
Owner: Emmanuel Technology Consulting
Former Sophos SG(Astaro) advocate/researcher/Silver Partner
PfSense w/Suricata, ntopng,
Other addons to follow
Owner: Emmanuel Technology Consulting
Former Sophos SG(Astaro) advocate/researcher/Silver Partner
PfSense w/Suricata, ntopng,
Other addons to follow
after reboot, upload speed is about 25-mbps (half of normal 50-mbps)
IPS log is empty after reboot....thanks for all inputs....no input from Sophos yet
Barry,
It was logging UDP-4500 flood for the NAT-VPN, but this is not correct since our Cisco IPS was not seeing it.
Thanks for checking. No update from Sophos
Owner: Emmanuel Technology Consulting
Former Sophos SG(Astaro) advocate/researcher/Silver Partner
PfSense w/Suricata, ntopng,
Other addons to follow
The "UDP-4500 flood" was a valid NAT-IPsec request from a VPN peer.
So current state as follows:
1. Global IPS enabled, the rest are disabled: TCP/UDP/ICMP DoS and Anti-Portscan disabled, Pattern disabled.
2. Threat Detection enabled.
3. Antivirus and Anti-Spyware disabled.
4. Hot-Standby
5. Several Parent Proxies connected using IPSec VPN tunnels.
6. Several Web Filter Profiles pointing to unique Parent Proxy, and block personnal emails (Gmail, Hotmail, etc.)
7. Several interfaces (Vlans/Subnets) for wired clients.
8. CPU= 2%, Memory=10%
9. Users= 5 (designed for many-many users).
Performance:
download= normal at about 50-mbps
upload= half normal about 25-mbps
thanks...
Owner: Emmanuel Technology Consulting
Former Sophos SG(Astaro) advocate/researcher/Silver Partner
PfSense w/Suricata, ntopng,
Other addons to follow