Hi,
we have two completly separate HA clusters (SG430 and SG210) which showed the same behaviour at the same time. Suddenly the cpu spikes up to 99% and thus turning down network functionality. we have looked into the following:
1. Update firmware (to 9.721) and pattern (other cluster with the same pattern do not expirience this behaviour)
2. Reboots on both nodes
3. Postgres rebuilds
4. Looking for large amounts of unusual traffic like from a DDoS attack -> none
After firmware Update and postgres rebuilds it stabalized on both nodes but it ist still 20-30% above whats normal
a "top" showd that it is httpproxy that leads to that cpu usage, but I cannot wrap my head around what caused this sudden CPU spike as the proxy is not used more or less than before...
Appreciate some opinions or solutions if any are applicable.
Kind Regards, Niclas
Hi Niclas Lilie ,
Thank you for reaching out to the community, you can refer the following for the better understand - Sophos Firewall: Understanding “top” and “atop” command in Sophos Firewall/UTM - Recommended Reads - Sophos Firewall - Sophos Community - Connect, Learn, and Stay Secure
Thanks & Regards,
_______________________________________________________________
Vivek Jagad | Team Lead, Technical Support, Global Customer Experience
Log a Support Case | Sophos Service Guide
Best Practices – Support Case | Security Advisories
Compare Sophos next-gen Firewall | Fortune Favors the prepared
Sophos Community | Product Documentation | Sophos Techvids | SMS
If a post solves your question please use the 'Verify Answer' button.
Hi Vivek, I did review the link but nothing of interest there, except the already stated.
Did you notice anything suspicious in the http logs, fallback, kernel or system logs?
Thanks & Regards,
_______________________________________________________________
Vivek Jagad | Team Lead, Technical Support, Global Customer Experience
Log a Support Case | Sophos Service Guide
Best Practices – Support Case | Security Advisories
Compare Sophos next-gen Firewall | Fortune Favors the prepared
Sophos Community | Product Documentation | Sophos Techvids | SMS
If a post solves your question please use the 'Verify Answer' button.