New Sophos Support Phone Numbers in Effect July 1st, 2023

SASI high CPU usage

Hi there!

I'm currently running on SFVH (SFOS 19.5.0 GA-Build197) and notice a very high CPU usage caused by the SASI service. I tried to turn off Anti-Spam in my E-Mail profile, but it didn't change. 

TOP:

Control Center:

The only thing I could find was a periodic error while trying to download some Checksums (?) in the sasi.log:

Any ideas? Did anyone observe anything similar? Maybe even a fix?

Regards,

Patrick



Added TAGs
[edited by: Erick Jan at 9:39 AM (GMT -8) on 2 Mar 2023]
Parents Reply
  • Hi,

    your answer does cause me some concern. A user firewall rule is capable of blocking traffic that is not recorded in any report and would not not show up in the log viewer review of that firewall rule.

    The traffic does not show up in daily WAN usage so how is a user supposed to identify a failure?

    Ian

    XG115W - v19.5.2 mr-2 - Home

    If a post solves your question please use the 'Verify Answer' button.

Children
  • Hi there

    I replied to Janos yesterday. My Sophos firewall is directly connected to my ISP without any active network device in between. I noticed however that trying to download the SASI DB checksum via terminal (curl command) and force it to use IPv4 (curl -ipv4), it works fine every time. If I force it to use IPv6 (curl -ipv6) it fails most of the time (curl gets stuck and has t obe aborted). Ping and Traceroute to the SASI server however work for both IPv4 and IPv6 directly from the firewall's terminal. 

    Regards, Patrick