This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

IPS throughput again

Hello,

Yet another IPS question, like many others in the past. I have searched the old threads in the forum related to IPS, but could not find an answer to my question (maybe i missed something).

I am running Sophos UTM 9.705-3 virtualized on ESXi. It has 4 GB RAM and 4 cores assigned (the CPU barely goes over 2% usage).

My internet subscription is 500Mbps. 

The question here is regarding the IPS performance. When i keep the IPS disabled, a speed test shows about 440Mbps, which is fine.

When i enable the IPS (local networks->only one host) even with NO ATTACK PATTERN ticked, the speed test does not go over 320 Mbps. So i loose 100Mbps only by activating this feature; if i start to tick few attack patterns like malware and windows (time 6 months) the speed drops to 290 Mbps and of course, if i tick more and more patterns, the speed drops accordingly.

I have played with the recommendations here https://support.sophos.com/support/s/article/KB-000034986?language=en_US&c__displayLanguage=en_US   , but the result is the same.

Am i doing something wrong, or this is a normal behavior of the IPS engine (eating a lot of bandwidth even in idle times) ?

Thanks



This thread was automatically locked due to age.
Parents Reply Children
  • i tried it now, with value 3 and 2, 4 - it is even a bit worse than with the default value.

  • This sounds like you are having vmware performance issues.  Running a speedtest.net on a pipe that big should basically pound 1 cpu core.  I don't use vmware, but maybe look into cpu pinning/affinity to see if dedicated 1-1physical to virtual cpu cores increases your performance and resulting report of how hard the cpu is getting hit in UTM itself.

  • Salut Panicos,

    It doesn't help to set num_instances to 3 in this case.  The default is 0 which means N-1 and that's 3 already.

    320 Mbps is the best you can get with a single thread with that CPU.  Try running the speedtest simultaneously from two computers and you will get a total of 500Mbps.

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA