• IPS is slowing down internet speed and causing Packet-loss on WAN interface

    Hello Community, We have a UTM SG430 and 1GBit/s internet connection. Now I have noticed that IPS a. prevents the line from being fully utilized. b. Long response times (100ms-500ms) and even packet loss occur when the WAN interface is heavily utilized…
  • IPS, the firewall,RED networks, and bypassing for MSFT IPs.

    Hello all, May be a silly question, however, in the IPS service: Do we need to include the RED networks for remote offices as well? Similarly, do they (RED networks) need to be listed in the Firewall rule for Teams and the like: Finally, besides…
  • Snort - no such file or directory

    Just installed Sopos UTM 9.707-5 in esxi vmware. When starting Intrusion Prevention I see in the console: /usr/bin/chroot: failed to run command '/sbin/snort' no such file or directory I have ssh'd in to the utm and checked, snort can't be found…
  • Poor IPS perf - "Multithreaded" snort not working?

    Hi all. I have a custom built router using a Gigabyte J1900N-D3V board. To cut it short, inter-VLAN traffic is limited to about 200mbit, but the CPU utilization only ever hits ~30%. Of course standard snort does not take advantage of the multiple cores…
  • Sophos UTM 9.705-3 Intrusion Prevention

    Hello, I appear to be having some trouble with the Intrusion Prevention on my UTM. When I have Intrusion Prevention enabled, my network speeds are reduced dramatically. For example, my WAN connection; with and without Intrusion Prevention enabled: Enabled…
  • Intrusion Prevention Alert (Packet dropped)

    Hi guys, I keep getting the following alert and just wondered if it was anything to worry about / look further into: Intrusion Prevention Alert An intrusion has been detected. The packet has been dropped automatically. You can toggle this rule…
  • Can't seem to test trigger alerts on the Intrusion Prevention. . . is it even working?

    Hello all, We have a UTM 9 in the office and I was trying to test the Intrusion Prevention feature. So under local networks I setup a host basically my computer. And on another computer I used a program called IDSWakeup to hit it with different…
  • RE: Concurrent Connection issue still in 9.350-12

    Scoreboard is Full After going through countless logs I kept finding logs pertaining to “scoreboard is full”. I started seeing this log when we started to see large amounts of traffic on the utm. FYI: I currently utilize WAF and IPS on the utm. …
  • Lots of IPS attacks lately One CNC Trufflehunter cant find much info on it (False Positive?)

    We have been getting a LOT of IPS attacks lately. Getting Snort 38330 MALWARE-CNC TRUFFLEHUNTER SFVRT-1020 attack attempt from several internal IPs. Snort doesnt give much information.... is there a good chance these hosts are infected? Sophos Cloud AV…