Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Bandwidth getting pegged deploy.static.akamaitechnologies

Hi,

For the past couple weeks for about 4-5 hours at time we've been getting extremely high bandwidth usage on HTTP (deploy.static.akamaitechnologies.com).

The connection is a 100/100 - when this is happening the connection is stuck in the the upper 90's so it's capping the FW and making all internet pretty much unusable. 

I know this server can be used for many things (AV updates, content updates/streaming, and mostly from what I've seen when using WireShark during one of these occurences, Windows Updates).

I've tried putting in web filtering exceptions to bypass all checks for akamaitechnologies.com incase the traffic was getting stuck in there somehow.

I've also tried putting QoS rules to limit the Akamai Applications as well as the direct servers for some of the addressed in the flow log, they just switch to a different one and the traffic builds right back up.

 

I'm going to be putting a WSUS server in-place to hopefully help this but has anyone else had this issue or found to a way to limit this traffic so it doesn't hinder the entire network?

 

 

(215 GB of that HTTP traffic was akamaitechnologies.com)

 

What the flow monitor looks like while it's happening.

 

 



This thread was automatically locked due to age.
Parents
  • Edit:

    So strangely, clearing the cache on the web filter dropped the bandwidth from 95+/100 Mbit to 20/100 Mbit within about 10 seconds and has completely normalized since.  I do not have web caching enabled so why would clearing that do anything...?

     

    Firmware 9.405-5

  • We haven't seen this in quite awhile here.  My guess is that it's used by the AV while scanning inbound traffic and sometimes that causes issues that result in the same file being sent simultaneously in multiple streams.  If you can identify the download that might have caused this, you could try an AV Exception.  Since we don't have more raw data about this, it's just a WAG on my part!

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
Reply
  • We haven't seen this in quite awhile here.  My guess is that it's used by the AV while scanning inbound traffic and sometimes that causes issues that result in the same file being sent simultaneously in multiple streams.  If you can identify the download that might have caused this, you could try an AV Exception.  Since we don't have more raw data about this, it's just a WAG on my part!

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
Children
No Data
Share Feedback
×

Submitted a Tech Support Case lately from the Support Portal?