Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Another "slow IPS" thread :-)

Hi all,

Happy New Year :-)

Let me start to say that I am not pointing fingers at IPS here, this is something with my Home UTM setup :-)

I got an ISP upgrade, so that I now have 300 download and 60mbit upload on a cable connection.

My setup:

Running VMWARE ESXi 6 on a HP Proliant Microserver gen8 with  Intel(R) Xeon(R) CPU E3-1220L V2 @ 2.30GHz CPU

The UTM is configures with:

2 vCPU's (1 socket / two cores)

4Gb ram.

60Gb SSD (raid1)

2 NIC's (Both VMXNET3) running trunk ports to a HP switch (Lan: Default VLAN and WAN VLAN xxx)

For this test i have powered off ALL other VM's on the server.

Problem is that with only IPS enabled i can fetch 240MBIT down and 60Mbit upload, well that is good enough for my little family, no question about that!

But as the nerd i am, I want to know why i get 300Mbit download if i disable IPS.

I have seen this in the IPS log when i do bandwidth tests:

 

And I read this thread:

https://community.sophos.com/products/unified-threat-management/f/network-protection-firewall-nat-qos-ips/79574/seeing-session-exceeded-configured-max-bytes-to-queue-in-ips-logs

Tried both BALFSON's tip and SACHING, but with no luck.

I can do a reinstall and change the CPU to 2 sockets and 2 cores each, giving the double power (At least I THINK i have to reinstall when doing that?!? - too many files to change)

Is the servers CPU too slow (I recon not?!) or is it the VMWARE overlay?

I use DHCP wan and use the MTU fix as i otherwise get MTU 576 but now have MTU 1500.

But as stated earlier, enabling everything in the UTM without IPS, gives the full monty :-)

So more CPU power or some tweaking??

Thanks in advance :-)



This thread was automatically locked due to age.
  • Hi Martin,

    I bet you won't get better than that throughput for a single connection with 2.30GHz.  I didn't follow your description of your VM well enough to know whether two different connections would each use a different core for Snort.

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
  • Hi Bob,

     

    Okay, so I need faster hardware I guess, well it makes perfectly sense :-)

    Is there a math equation that equals "bandwidth = this CPU" ? :-)

    -----

    Best regards
    Martin

    Sophos XGS 2100 @ Home | Sophos v19 Architect

  • Look for threads by William and at the thread at the top of the Hardware forum.  You'll see that the fastest CPUs can handle 300Mbps per connection.  A quad core CPU running at 3+GHz reportedly can fill a 1Gbps pipe with a sufficient number of simultaneous downloads.

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
  • Thanks - will look at that :-)

    Have a great weekend :)

    -----

    Best regards
    Martin

    Sophos XGS 2100 @ Home | Sophos v19 Architect

Share Feedback
×

Submitted a Tech Support Case lately from the Support Portal?