Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Sophos XG2100 High single core usage - SNORT

Hi All 

Hope someone can assist. 

Every couple of days we see 100% CPU usage on a single core. Not the same core every time. 

The core then sits at 100% CPU for 2 to 6 hours then a couple of days later same thing. 

I have checked and it is the SNORT process causing this. 

When I disable IPS the CPU usage drops instantly. 

Anyone that can assist in helping me figure out WHY this is happening? 

Firmware: SFOS 19.5.4 MR-4-Build718

No of policies using IPS: 4 (all LAN to WAN) 

Two of the policies are tunnel mode SSL VPN so it gets internet via the VPN. 

All policies have web filter applied with about  40 URLs as a whitelist. 

Couple of exemptions. configured with the * at the start. 

Average CPU usage is 40% - 45%. 

Thanks 



This thread was automatically locked due to age.
Parents Reply Children
No Data