Hi,
I have been troubleshooting performance issues on a 300Mbit WAN link, firstly I have customer running in VMWARE as Software edition, but 236Mbit was the max. I then looked at the specs for SG210:
We had one laying around, and we took it to the customer, but sadly same result :-(
As I read, the SG210 should handle 500mbit with IPS/AV proxy enabled?!
The issue is IPS, when I disable it on SG210 or the software version, we can hit 326Mbit with proxy on or off.
I get theese in IPS log:
2017:04:02-09:54:16 fw02 snort[26955]: S5: Session exceeded configured max bytes to queue 3257045 using 3259676 bytes (client queue). 192.168.110.55 50474 --> 195.137.194.230 8080 (0) : LWstate 0xf LWFlags 0x406007
2017:04:02-09:54:16 fw02 snort[26955]: S5: Session exceeded configured max bytes to queue 3257045 using 3259461 bytes (client queue). 192.168.110.55 50468 --> 195.137.194.230 8080 (0) : LWstate 0xf LWFlags 0x406007
I have read in the forum and changed max_queued_bytes and used commands "cc set ips snortsettings max_queued_bytes 3257045" and "cc set ips queue_length 8192", but with no luck.
But I wonder, why can't SG210 out of the box, with no IPS modification, handle this at all?
IPS patterns are default 12months.
Help help help :-)
This thread was automatically locked due to age.