I have been running an ASG220 for about 10 months now. It is currently running version 6.304 (and I have no plan to upgrade to 7 due to the amounts of problems/bugs being reported).
I am making use of the following services:
HTTP proxy
SMTP proxy
IDS/IPS
Packet filtering (obviously)
My biggest problem with this device is that it kept timing out whenever I try to edit an IPS rule or when I edit the spam quarantine. In addition, I also have a lot of dropped PPTP as well as L2TP VPN connections.
Astaro techs said it might be because the box is overloaded. CPU usage is less than 1 for almost 95% of the time. The other 5% is are when it spikes up to 4-10. I noticed that, whenever I edit an IPS rule or muck around with the quarantine, CPU usage shoots up to at least 6, which Astaro techs says might be the problem. However, I have two arguments here:
1) I understand CPU usage should spike when a large list (such as IPS rules or spam quarantine) is being loaded, but I was using the filter feature to list and edit 1 rule. Also, it did not timeout when the rules are being listed. It timed out right after I made the change to drop/allow or disable/enable the rule.
2) Whatever may happen in regards to listing and editing rules, traffic between the various interfaces should NEVER timeout, unless it was a misconfiguration (packet filter rule to block traffic, IPS rule to drop traffic, etc.).
3) The Astaro techs say that spikes in CPU usage is normal but they shouldn't cause timeouts. Well, almost every single time I have a spike above 4, I experience a timeout on the firewall's interfaces, and I can replicate this pretty easily by just editing an IPS rule, sometimes just listing the rule (using the filter tool) is enough to cause the timeout.
The primary reason we bought the ASG 220 was to have it filter traffic between its 8 interfaces. However, I can't depend on it being the middle man between my various networks if it times out so easily and so frequently. Depending on the application, communication between entire subnets can be severely interrupted when the ASG times out like this.
Is anybody having the same problem?
This thread was automatically locked due to age.