Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Performance issues with IPS on SG210

Hi,

I have been troubleshooting performance issues on a 300Mbit WAN link, firstly I have customer running in VMWARE as Software edition, but 236Mbit was the max. I then looked at the  specs for SG210:

 

We had one laying around, and we took it to the customer, but sadly same result :-(

As I read, the SG210 should handle 500mbit with IPS/AV proxy enabled?!

The issue is IPS, when I disable it on SG210 or the software version, we can hit 326Mbit with proxy on or off.

I get theese in IPS log:

2017:04:02-09:54:16 fw02 snort[26955]: S5: Session exceeded configured max bytes to queue 3257045 using 3259676 bytes (client queue). 192.168.110.55 50474 --> 195.137.194.230 8080 (0) : LWstate 0xf LWFlags 0x406007
2017:04:02-09:54:16 fw02 snort[26955]: S5: Session exceeded configured max bytes to queue 3257045 using 3259461 bytes (client queue). 192.168.110.55 50468 --> 195.137.194.230 8080 (0) : LWstate 0xf LWFlags 0x406007
 
I have read in the forum and changed max_queued_bytes and used commands "cc set ips snortsettings max_queued_bytes 3257045" and "cc set ips queue_length 8192", but with no luck.
 
But I wonder, why can't SG210 out of the box, with no IPS modification, handle this at all?
 
IPS patterns are default 12months.
 
Help help help :-)
 


This thread was automatically locked due to age.
Parents Reply Children
No Data