Owner: Emmanuel Technology Consulting
Former Sophos SG(Astaro) advocate/researcher/Silver Partner
PfSense w/Suricata, ntopng,
Other addons to follow
how many users? which features? what version of UTM software?
Owner: Emmanuel Technology Consulting
Former Sophos SG(Astaro) advocate/researcher/Silver Partner
PfSense w/Suricata, ntopng,
Other addons to follow
This is a graph of our CPU usage. It's pretty apparent when httpprox is consuming CPU.
Owner: Emmanuel Technology Consulting
Former Sophos SG(Astaro) advocate/researcher/Silver Partner
PfSense w/Suricata, ntopng,
Other addons to follow
first off update to 9.306 if you have the files available if not i can post links.(do this during a maintenance window). also have you contacted support? http proxy hanging on 40% could be a bad pattern update.
Thanks for the reply. I'll update to 9.306 tonight and post back with results. I've contacted our reseller (we lease the firewall through our ISP). They said it may be an AV scanning issue, and to let them know if it continues. It seems to happens whether we have single-scan set to the Sophos or Avira engines.
Owner: Emmanuel Technology Consulting
Former Sophos SG(Astaro) advocate/researcher/Silver Partner
PfSense w/Suricata, ntopng,
Other addons to follow
oh there was some kind of bug involving a/v and single scanning. Frankly i would try dual-scanning and leave it on..greater security. it will increase cpu but unless it starts affecting performance the extra security is worth it. I always run dual-scan a/v.
OK, I'll turn on dual-scan when I update to 9.306 and report back.
I should clarify that CPU graph. The part where it drops back down at the end of yesterday is when I restarted the firewall. Once httpprox gets pegged, it will stay that way (after hours, when there's very little traffic going through) until the fw or web filtering is restarted.
Regarding AV scanning - what do you recommend for the upper file size limit for scanning?
Owner: Emmanuel Technology Consulting
Former Sophos SG(Astaro) advocate/researcher/Silver Partner
PfSense w/Suricata, ntopng,
Other addons to follow
oh there was some kind of bug involving a/v and single scanning. Frankly i would try dual-scanning and leave it on..greater security. it will increase cpu but unless it starts affecting performance the extra security is worth it. I always run dual-scan a/v.