This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

IPS Blocking legit traffic speedtest.net / IPS impacting performance even if IPS is not enable in the rule

I get thousands of this alerts every time I use https://www.speedtest.net/

 

"Data sent on stream after TCP Reset received"

Does it make sense? how can I disable it or fix the issue?
The IP belongs to the service
 
It's a bug?


This thread was automatically locked due to age.
Parents Reply Children
  • For the firewall rule affected I only have web filering.

    I only have IPS active in a rule that only affect to a host, so the speed test has nothing to do with it

    The only way to get 300 Mbps of upload is if I stop the IPS service completetly in "System Services" -> "Services"

    It looks like a wrong implementation of Snort in Sophos XG, how my upload speed can be capped if I dont have the IPS active in any rule?

  • You might want to remove the web filter as well from the speediest rule.

    Ian

    Also found that speediest.net goes to a lot of sites that are not part of its FDQN which causes failures if you use their FQDN in the allowed rule.

    XG115W - v20 GA - Home

    XG on VM 8 - v20 GA

    If a post solves your question please use the 'Verify Answer' button.

  • To add image context to the settings that Ian mentioned:


    Florentino
    Director, Global Community & Digital Support

    Are you a Sophos Partner? | Product Documentation@SophosSupport | Sign up for SMS Alerts
    If a post solves your question, please use the 'Verify Answer' button.
    The Award-winning Home of Sophos Support Videos! - Visit Sophos Techvids
  • Hi Flo,

    my apologies, I took that comment out after much testing and could not see any changes to my download speeds using speediest.net.

    Further my settings  for the IPS are not the default, but updated from previous recommendations on how to block some unwanted software/access.

    What Idid find was that limiting the speediest.net to its FQDN sites caused it to fail, but no restrictions on download or upload performance.

    I will run some more tests with IPS enabled in the speediest rule and report back.

    Ian

    XG115W - v20 GA - Home

    XG on VM 8 - v20 GA

    If a post solves your question please use the 'Verify Answer' button.

  • Update on testing.

    My IPS settings had no affect on the speedtest.net performance. I have tuned my IPS policy.

    Using http/s as the allowed protocols caused the tests to run very slow with block unknown protocols disabled. Also required an update to flash part the way through the test.

    Ian

    XG115W - v20 GA - Home

    XG on VM 8 - v20 GA

    If a post solves your question please use the 'Verify Answer' button.

  • Do you mean that I should disable this 2 options? they were enable by default

  •   

    All I know is that if I have the IPS enable

    And this as the only rule with IPS enable

    my CPU while doing a https not managed by that rule download at 30MB/s look like this, (CPU5 and 7 are not attached to Sophos XG)

    As far as I know this traffic shouldn't be analyzed by Sophos XG because the rule managing this traffic doesn't have IPS enable.

    Then if I disable the IPS Service

    under the same conditions my CPU utilization is:

     

    So obviously the IPS is analysing traffic that it should not analyze, and this is a bad implementation of Snort, this https traffic should go through the firewall without and the IPS should not penalized the firewall performance.

     

    I'm pretty sure this is a bug, could you bring this to sophos XG engineers to study it and fix it?

    In other firewalls the IPS only works if the rule associated to the IPS is managing traffic, in Sophos XG is not the case.

  • If you have DOS enabled it will examine all traffic for all rules as distinct from have a specific set of IPS rules for each firewall rule.

    Ian

    XG115W - v20 GA - Home

    XG on VM 8 - v20 GA

    If a post solves your question please use the 'Verify Answer' button.

  • Now I have disable DoS settings

    And again under the same conditions the CPU load seems to be similar

     

     

    My rules

     

    IPS service disable and DoS settings disable:

     

  •  

     

    I have replicated the test, this time with speedtest.

    IPS engine Enable DoS Disable

     

    IPS engine Disable DoS Disable