This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Performance issues with IPS on SG210

Hi,

I have been troubleshooting performance issues on a 300Mbit WAN link, firstly I have customer running in VMWARE as Software edition, but 236Mbit was the max. I then looked at the  specs for SG210:

 

We had one laying around, and we took it to the customer, but sadly same result :-(

As I read, the SG210 should handle 500mbit with IPS/AV proxy enabled?!

The issue is IPS, when I disable it on SG210 or the software version, we can hit 326Mbit with proxy on or off.

I get theese in IPS log:

2017:04:02-09:54:16 fw02 snort[26955]: S5: Session exceeded configured max bytes to queue 3257045 using 3259676 bytes (client queue). 192.168.110.55 50474 --> 195.137.194.230 8080 (0) : LWstate 0xf LWFlags 0x406007
2017:04:02-09:54:16 fw02 snort[26955]: S5: Session exceeded configured max bytes to queue 3257045 using 3259461 bytes (client queue). 192.168.110.55 50468 --> 195.137.194.230 8080 (0) : LWstate 0xf LWFlags 0x406007
 
I have read in the forum and changed max_queued_bytes and used commands "cc set ips snortsettings max_queued_bytes 3257045" and "cc set ips queue_length 8192", but with no luck.
 
But I wonder, why can't SG210 out of the box, with no IPS modification, handle this at all?
 
IPS patterns are default 12months.
 
Help help help :-)
 


This thread was automatically locked due to age.
  • Logged support ticket :-)

    -----

    Best regards
    Martin

    Sophos XGS 2100 @ Home | Sophos v20 Architect

  • Hi Martin, 

    Try this, SSH to the UTM as super user and execute.

    cc set ips queue_length 8192

    Increasing queue_lenth will result in higher value for memcap eventually, more packets can be scanned through it. Also, refer the document here.

    Hope that helps.

    Sachin Gurung
    Team Lead | Sophos Technical Support
    Knowledge Base  |  @SophosSupport  |  Video tutorials
    Remember to like a post.  If a post (on a question thread) solves your question use the 'This helped me' link.

  • Hi saching,

    Thanks for replying :-)

     

    I already did that and also wrote it in my first post (a little to hidden maybe), but it did not change anything.

    -----

    Best regards
    Martin

    Sophos XGS 2100 @ Home | Sophos v20 Architect

  • Hi Martin,

    did you check the speed with only one dowload? Please try with more downloads at the same time. With just one download, you never reach the maximum download rate with IPS on a SG 210.

    regards

    mod

  • Hi mod ;)

    Yes I have tried to different speedtest site, each capable of giving me 300+ mbit with IPs of, but when eI turn IPS on, the on takes it all and the other stays at 7-8Mbit until first test is done, then it increases.

     

    Why can't SG210 handle this with dual core cpu?

     

    because one core for ips, and only 236Mbit each and the other core for os/services?

    -----

    Best regards
    Martin

    Sophos XGS 2100 @ Home | Sophos v20 Architect

  • Hi Martin,

    of course you are right. I have not thought that the sg210 has only a dual core cpu.

    I've no experience with SG 210 and 500Mbit WAN Speed. Did you have tested some iso downloads with ips turned on? I never use speedtest sites for such tests.

    I've experience with ASG 320, SG 330 and SG 430 with a 500Mbit WAN uplink and IPS turned on.

    The ASG 320 is absolutly to small for 500 Mbit with optimized IPS.

    An optimized SG 330 loads with about 350 Mbit up to 400 Mbit. (different ISO downloads at the same time)

    And finally the SG 430 loads with about 450 Mbit with optimized IPS. (different ISO downloads at the same time)

    regards

    mod

     

  • Interesting question, Martin.  Because of this, I've been recently been tempted to favor the SG 135 over the 210.  The 210 has more raw computing power, but it's dual-core whereas the 135 has a quad-core CPU.  Has anyone tested both devices to see if four simultaneous ISO downloads are faster on a 135 than on a 210?

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
  • Bob, I tried question :-)

    Took a SG210 and SG135 from work, using same config to both devices and running 9.411:

     

    Downloading Win 2012 R2 and Win Srv 2016 ISO from MS VLSC simultaniously:

    SG210:

     

    SG135:

    Look at the different throughput on both devices, SG210 one fast and one slow download, SG135 both fast downloads and more throughput.

     

    Speedtest SG210: 236Mbit

    Speedtest SG135: 180Mbit

    So there is really "Something about Mary" with the CPU/Cores when IPS is doing it's job :-)

    -----

    Best regards
    Martin

    Sophos XGS 2100 @ Home | Sophos v20 Architect

  • Thanks, Martin!  I would have expected the 210 to be faster with just two downloads - does a second trial produce the same results?

    What about four simultaneous downloads on each? - That's where I expect (guess) the 135 will really beat the 230.

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
  • 4 downloads:

    SG210:

     

    SG135:

    Interesting! ;)

    -----

    Best regards
    Martin

    Sophos XGS 2100 @ Home | Sophos v20 Architect