Hello,
Last night I updated to firmware 9.108-23, from the previous level to that, and since then all downloads from the Google Play Store to my Android phone have been running SLOW!!! ~8kB per 20 seconds.
I found some entries in the IPS logs that looked suspicious, so I began disabling the rulesets one at a time until I found the one that cured the problem.
Turns out that "Malware (3407 attacks, 5296 warnings)" was the set of rules blocking traffic.
I'm putting this info here in case anyone else runs into the same issue - they can see what to disable to get things going again.
Anyway, the IPS log contained (this is just a sample):
2014:02:19-19:23:46 fw snort[18669]: id="2101" severity="warn" sys="SecureNet" sub="ips" name="Intrusion protection alert" action="alert" reason="BAD-TRAFFIC TMG Firewall Client long host entry exploit attempt" group="500" srcip="192.168.5.253" dstip="192.168.5.5" proto="17" srcport="53" dstport="59833" sid="19187" class="Attempted User Privilege Gain" priority="1" generator="3" msgid="0"
2014:02:19-19:24:01 fw snort[18672]: id="2101" severity="warn" sys="SecureNet" sub="ips" name="Intrusion protection alert" action="alert" reason="BAD-TRAFFIC TMG Firewall Client long host entry exploit attempt" group="500" srcip="192.168.5.253" dstip="192.168.5.55" proto="17" srcport="53" dstport="19701" sid="19187" class="Attempted User Privilege Gain" priority="1" generator="3" msgid="0"
2014:02:19-19:24:02 fw snort[18669]: id="2101" severity="warn" sys="SecureNet" sub="ips" name="Intrusion protection alert" action="alert" reason="APP-DETECT Dropbox desktop software in use" group="500" srcip="192.168.5.5" dstip="108.160.162.37" proto="6" srcport="61072" dstport="80" sid="18608" class="Potential Corporate Privacy Violation" priority="1" generator="1" msgid="0"
2014:02:19-19:24:03 fw snort[18672]: id="2101" severity="warn" sys="SecureNet" sub="ips" name="Intrusion protection alert" action="alert" reason="OS-MOBILE Android User-Agent detected" group="500" srcip="192.168.5.66" dstip="202.125.44.161" proto="6" srcport="43048" dstport="80" sid="25521" class="Potential Corporate Privacy Violation" priority="1" generator="1" msgid="0"
2014:02:19-19:24:03 fw snort[18672]: id="2101" severity="warn" sys="SecureNet" sub="ips" name="Intrusion protection alert" action="alert" reason="OS-MOBILE Android User-Agent detected" group="500" srcip="192.168.5.66" dstip="202.125.44.161" proto="6" srcport="43048" dstport="80" sid="25521" class="Potential Corporate Privacy Violation" priority="1" generator="1" msgid="0"
2014:02:19-19:24:03 fw snort[18667]: id="2101" severity="warn" sys="SecureNet" sub="ips" name="Intrusion protection alert" action="drop" reason="FILE-OTHER Corel PDF fusion XPS stack buffer overflow attempt" group="500" srcip="150.101.213.145" dstip="192.168.5.55" proto="6" srcport="80" dstport="47122" sid="29466" class="Attempted User Privilege Gain" priority="1" generator="1" msgid="0"
2014:02:19-19:24:34 fw snort[18669]: id="2101" severity="warn" sys="SecureNet" sub="ips" name="Intrusion protection alert" action="alert" reason="BAD-TRAFFIC TMG Firewall Client long host entry exploit attempt" group="500" srcip="203.0.178.191" dstip="192.168.5.223" proto="17" srcport="53" dstport="38946" sid="19187" class="Attempted User Privilege Gain" priority="1" generator="3" msgid="0"
This thread was automatically locked due to age.