I noticed it in my own network, and have confirmed in the forums that IPS causes some major performance loss. Curious - is it the overall feature being turned on, or particular pieces? Anyone done some testing with this? Example - Can leave anti-portscan and DoS protection on, but turn off all attack patterns?
It just bugs the hell out of me knowing the units I just purchased kill my bandwidth using one of the primary features drawing me to Sophos UTMs.
A number of my sites still run on 1-2 T1s and can't afford to take any hits to their bandwidth.
Thanks!
-Jim
Owner: Emmanuel Technology Consulting
Former Sophos SG(Astaro) advocate/researcher/Silver Partner
PfSense w/Suricata, ntopng,
Other addons to follow
The reduction in speed has been reported at all sites where a UTM was installed.
Sites:
3-6 users, UTM 110
3-6 users, UTM 110
50+ users, UTM 320
My configurations are pretty basic. Turned on IPS, enabled relevant features throughout, nothing wild.
Don't these thread somewhat confirm performance loss using IPS?
http://www.astaro.org/gateway-products/network-protection-firewall-nat-qos-ips/50922-bandwidth-hit-ips.html
http://www.astaro.org/gateway-products/network-protection-firewall-nat-qos-ips/49475-ips-performance-problem-100mbit-fiber.html
-Jim
Owner: Emmanuel Technology Consulting
Former Sophos SG(Astaro) advocate/researcher/Silver Partner
PfSense w/Suricata, ntopng,
Other addons to follow
The reduction in speed has been reported at all sites where a UTM was installed.
Sites:
3-6 users, UTM 110
3-6 users, UTM 110
50+ users, UTM 320
My configurations are pretty basic. Turned on IPS, enabled relevant features throughout, nothing wild.
Don't these thread somewhat confirm performance loss using IPS?
http://www.astaro.org/gateway-products/network-protection-firewall-nat-qos-ips/50922-bandwidth-hit-ips.html
http://www.astaro.org/gateway-products/network-protection-firewall-nat-qos-ips/49475-ips-performance-problem-100mbit-fiber.html
-Jim
Owner: Emmanuel Technology Consulting
Former Sophos SG(Astaro) advocate/researcher/Silver Partner
PfSense w/Suricata, ntopng,
Other addons to follow
The reduction in speed has been reported at all sites where a UTM was installed.
Sites:
3-6 users, UTM 110
3-6 users, UTM 110
50+ users, UTM 320
My configurations are pretty basic. Turned on IPS, enabled relevant features throughout, nothing wild.
Don't these thread somewhat confirm performance loss using IPS?
http://www.astaro.org/gateway-products/network-protection-firewall-nat-qos-ips/50922-bandwidth-hit-ips.html
http://www.astaro.org/gateway-products/network-protection-firewall-nat-qos-ips/49475-ips-performance-problem-100mbit-fiber.html
-Jim
Owner: Emmanuel Technology Consulting
Former Sophos SG(Astaro) advocate/researcher/Silver Partner
PfSense w/Suricata, ntopng,
Other addons to follow
Lol... seeing as how you used the word "Morman", I have a feeling you are on a cell?
Site 1 + 2
- UTM 110 (9.107-33)
- 3-6 users
- Bonded T1's, 3m up/down. Generally see lower speeds, like 2/2.
- IPS Turned on
- Operating sys attacks -> windows
- Attacks against client software -> all
- Protocol anomoly
- malware
- TCP Syn Flood
- ICMP Flood
- Anti-portscan - drop traffic
Site 3
- UTM 320 (9.107-33)
- 50+ users, 10 servers, over 200 total devices
- 20m Ethernet over fiber, soon to be upgraded to 50m
- IPS Turned on
- ALL attack patterns turned on
- TCP Syn Flood
- ICMP Flood
- Anti-portscan - drop traffic
Owner: Emmanuel Technology Consulting
Former Sophos SG(Astaro) advocate/researcher/Silver Partner
PfSense w/Suricata, ntopng,
Other addons to follow