Dear All,
my system has 4 GB of RAM and with EAP2, memory utilisation is 84%.
Sophos: is this the normal or what you expect for such a system?
Thanks
Dear All,
my system has 4 GB of RAM and with EAP2, memory utilisation is 84%.
Sophos: is this the normal or what you expect for such a system?
Thanks
My RAM usage is around 39% in EAP 2. On Sophos XG Home, 8GB on system - 6GB usable.
After i found out Snort on XG supported hyperscan, and my NIC chipset also supported, I've decided to give it a try. RAM usage has lowered in 1GB after this change.
If a post solves your question use the 'Verify Answer' button.
Ryzen 5600U + I226-V (KVM) v21 GA @ Home
Sophos ZTNA (KVM) @ Home
Prism said:My RAM usage is around 39% in EAP 2. On Sophos XG Home, 8GB on system - 6GB usable.
After i found out Snort on XG supported hyperscan, and my NIC chipset also supported, I've decided to give it a try. RAM usage has lowered in 1GB after this change.
How come you're limited to 6GB usable? I'm on a Sophos XG Home license as well but with EAP, I'm able to utilize all 8GB.
How do you enable hyperscan?
---
Sophos XG guides for home users: https://shred086.wordpress.com/
shred said:How come you're limited to 6GB usable? I'm on a Sophos XG Home license as well but with EAP, I'm able to utilize all 8GB.
By default the Home License is limited to 6GB of ram, but apparently on EAP there's no RAM or CPU Limit, since i has able to use 8C/16GB on a VM.
shred said:How do you enable hyperscan?
If you have a Intel CPU and Intel NIC, you can enable it by running: "set ips search-method hyperscan" In the XG Console.
And then check if it has enable with: "show ips-settings"
There has a noticeable performance improvement with it, and also an huge RAM usage decreased by Snort. Which are both expected with Hyperscan.
If a post solves your question use the 'Verify Answer' button.
Ryzen 5600U + I226-V (KVM) v21 GA @ Home
Sophos ZTNA (KVM) @ Home
Thanks. Mine was defaulted to the "search_method ac-q". I enabled hyperscan and my RAM utilization dropped from 48% to now 35% (also running 8GB of RAM).
---
Sophos XG guides for home users: https://shred086.wordpress.com/
From memory if you used the upgrade from v17 memory cap changed, but if like me you did rebuilds using the ISOs the home licence memory cap remained at 6gb.
Ian
XG115W - v20.0.2 MR-2 - Home
XG on VM 8 - v21 GA
If a post solves your question please use the 'Verify Answer' button.
What are the trade-offs for using hyper scan?
Ian
XG115W - v20.0.2 MR-2 - Home
XG on VM 8 - v21 GA
If a post solves your question please use the 'Verify Answer' button.
Ian,
more info can be found here.
http://manual-snort-org.s3-website-us-east-1.amazonaws.com/node16.html
In the link, search for "search-method"
Regards
rfcat_vk said:What are the trade-offs for using hyper scan?
There's no trade-offs,
Hyperscan have a lower memory footprint and higher performance, if implemented correctly with Snort you could see almost 6x higher performance with it. And using at the same time 1/3 of the memory.
But i'm not seeing that huge difference with XG. I'll take this weekend to test the actual difference.
If a post solves your question use the 'Verify Answer' button.
Ryzen 5600U + I226-V (KVM) v21 GA @ Home
Sophos ZTNA (KVM) @ Home
nice, ram usage dropped from 76% (of 4GB) to 57%
Memory dropped immediately to 49% then rose to 60%.
So, no great improvement, but 10% is better then nothing.
The load has increased slightly. So monitoring over the next couple of days.
Ian
XG115W - v20.0.2 MR-2 - Home
XG on VM 8 - v21 GA
If a post solves your question please use the 'Verify Answer' button.
I do not get why using less than 75% memory is such a problem.
Seriously, who cares ?
I’m far more concerned about real life Firewall responsiveness than a race to use as least memory as possible .
Paul Jr
I do not get why using less than 75% memory is such a problem.
Seriously, who cares ?
I’m far more concerned about real life Firewall responsiveness than a race to use as least memory as possible .
Paul Jr
Because spare memory is used to cache, less disk access, faster user response, less swap especially on slower machines.
As we have seen 4gb systems were having issues so greducing memory use when you are limited to 4 or 6gb is worth the effort.
Ian
XG115W - v20.0.2 MR-2 - Home
XG on VM 8 - v21 GA
If a post solves your question please use the 'Verify Answer' button.
Big_Buck said:I do not get why using less than 75% memory is such a problem.
In my opinion, unused RAM is wasted RAM. But it's nice to see improvements on it.
Big_Buck said:I’m far more concerned about real life Firewall responsiveness than a race to use as least memory as possible .
Same thing,I believe people should be more worried about throughput and latency than RAM usage.
I'll be waiting for v18 to be officially released in 2020, on 2018 NSS labs test the average XG latency has too high compared to others vendors.
If a post solves your question use the 'Verify Answer' button.
Ryzen 5600U + I226-V (KVM) v21 GA @ Home
Sophos ZTNA (KVM) @ Home
There's the whole efficiency issue, but at 25% left, XG is not yet urgently required to tighten CPU hogging memory flushing procedures.
What I noticed with XGv17 is performance gains when increasing from 2 gig of memory to 4 gig are obvious. But from 4 gig to 8 gig, it is unnoticeable.
What I see is XGv17 becomes performance hit when memory utilisation is above 75%.
Paul Jr