<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="https://community.sophos.com/cfs-file/__key/system/syndication/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>XG 550 performance slow, high &amp;quot;Sessions&amp;quot; amount</title><link>https://community.sophos.com/sophos-xg-firewall/f/discussions/125609/xg-550-performance-slow-high-sessions-amount</link><description>We have an XG 550 rev. 2 configured with 2 different internet connections and a 10 gig fiber card for the LAN port. We have been experiencing DDOS attacks which we have an external service mitigating. What we have found is that at certain times during</description><dc:language>en-US</dc:language><generator>Telligent Community 12</generator><item><title>RE: XG 550 performance slow, high "Sessions" amount</title><link>https://community.sophos.com/thread/459230?ContentTypeID=1</link><pubDate>Thu, 28 Jan 2021 20:16:30 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:7b556ee4-71cf-4ce3-af47-e849bd46b64b</guid><dc:creator>BeEf</dc:creator><description>&lt;p&gt;Maybe DDoS mitigation is not working and the attack is coming from the other side ...&lt;/p&gt;
[quote userid="85479" url="~/xg-firewall/f/discussions/125609/xg-550-performance-slow-high-sessions-amount/459221#459221"]2) Set up a mirror port and try to find out whats actually happening.[/quote]&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: XG 550 performance slow, high "Sessions" amount</title><link>https://community.sophos.com/thread/459226?ContentTypeID=1</link><pubDate>Thu, 28 Jan 2021 19:56:59 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:3a02cada-c4ff-4741-89b4-c1d75672b20a</guid><dc:creator>Josh Rogalski</dc:creator><description>&lt;p&gt;We have 2 totally separate ISP&amp;#39;s that go into the XG 550 (with SD-Wan policy routes balancing traffic).&amp;nbsp; One has DDOS mitigation at the ISP level, and one doesn&amp;#39;t have it (being replaced later this year).&amp;nbsp; When we get attacked we have at times disconnected the 2nd line that doesn&amp;#39;t have DDOS protection on it.&amp;nbsp; It stops the attack from that unprotected line, but it feels like the appliance raises it&amp;#39;s sessions and memory just because that second line is disconnected. &lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: XG 550 performance slow, high "Sessions" amount</title><link>https://community.sophos.com/thread/459221?ContentTypeID=1</link><pubDate>Thu, 28 Jan 2021 19:38:06 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:a21c5c34-a485-4ad1-a5be-2b43700727c9</guid><dc:creator>BeEf</dc:creator><description>&lt;p&gt;1.8 Million is definitely too high.&lt;br /&gt;&lt;br /&gt;Could be some attack that is &amp;quot;consuming&amp;quot; sessions. Or maybe some packets with randomizes source addresses going against a service you are providing (e.g. Webserver, DNS, ...)&lt;br /&gt;&lt;br /&gt;1) Check the rules WAN -&amp;gt; LAN and whether IDS is switched on.&lt;br /&gt;&lt;br /&gt;2) Set up a mirror port and try to find out whats actually happening.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;I did not completely understand what you are doing with your two internet lines though ....&lt;br /&gt;&lt;br /&gt;(From our experience it is not possible to defend a DDoS attack on the device itself. So mitigating at the ISP is the way you need to do this. However be prepared that the second line could also be attacked (we noticed wandering of the attack depending on the provider ...).&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: XG 550 performance slow, high "Sessions" amount</title><link>https://community.sophos.com/thread/459195?ContentTypeID=1</link><pubDate>Thu, 28 Jan 2021 16:43:29 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:40000fbf-d098-4ebc-a2be-a92f9464bfb5</guid><dc:creator>LuCar Toni</dc:creator><description>&lt;p&gt;Sessions are basically conntrack table entries. Seems like some system is overload your system with sessions. You should get some expertise inhouse to find the Rootcause of this attacked.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;It could be a attack or a network issue with loops.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;p&gt;Maybe try the following:&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Conntrack is resonsible for the sessions in XG firewall.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;You can check which kind of connections is filling up this but you need Linux CLI knowledge to do so:&amp;nbsp;&lt;/p&gt;
&lt;p&gt;conntrack -L will list all current session (Basically 1.8M entries).&amp;nbsp;&lt;/p&gt;
&lt;p&gt;You can Pipe them up and start grap. conntrack -L | grep NEW | wc -l&amp;nbsp; &amp;nbsp; &amp;nbsp; Will list basically all new Sessions current seens and count them.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;a href="https://www.linuxtopia.org/Linux_Firewall_iptables/x1347.html"&gt;https://www.linuxtopia.org/Linux_Firewall_iptables/x1347.html&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item></channel></rss>