Welcome to the Sophos User Bulletin Board.
If this is your first visit, be sure to check out the FAQ by clicking the link above. You may have to register before you can post: click the register link above to proceed. To start viewing messages, select the forum that you want to visit from the selection below.

Like Tree8Likes

Reply
 
LinkBack Thread Tools Display Modes
Member
Join Date: Nov 2012
Posts: 62
#131 (permalink)  
Old 01-09-2013, 09:04 AM
Default

Quote:
Originally Posted by wingman View Post
Already did and the swap goes back to 90% within hours so At the moment I am restarting the box every night

Sent from my iPhone using Astaro.org
I have 120+ users and my ASG320 with 2GB RAM handles it.
Current system configuration
Firewall is active
Intrusion Prevention is inactive
Web Filtering is active
Network Visibility is active, 18 Application Control rules active
FTP Proxy is inactive
SMTP Proxy is active
POP3 Proxy is inactive
Web Application Firewall is active
Antivirus is active for protocols HTTP/S, SMTP, WAF
AntiSpam is active for protocols SMTP
AntiSpyware is active
Email Encryption is inactive
Site2Site VPN is inactive
Remote Access is active
HA/Cluster is inactive
Endpoint Protection is active
Wireless Protection is active
Reply With Quote
wingman's Avatar
Super Moderator
Join Date: Feb 2009
Location: In a galaxy far far away
Posts: 3,518
#132 (permalink)  
Old 01-09-2013, 10:45 AM
Default

Enabling the IPS ,FTP proxy ,pop3 proxy will bring your swap close to the figures that most of the other users report

I have only 3 uses and I am having such issues (well Support confirmed that there is a memory leak that is going to be resolved wt version 9.005)
__________________

Astaro ASG 120 Rev. 4 |Version 9.0** |1 X Astaro wireless AP10
Sophos UTM 120 Rev. 5 |Version 9.1** | 2 X Astaro wireless AP10
GPG Key Fingerprint: B205 ED94 FBF0 E617 63A5 C6C9 D15D 70A1 B84E 9AC9
Reply With Quote
Wizard
Join Date: May 2003
Location: Brunswick, Maryland, USA
Posts: 5,241
#133 (permalink)  
Old 01-09-2013, 12:15 PM
Default

Quote:
Originally Posted by pitonsxxl View Post
I have 120+ users and my ASG320 with 2GB RAM handles it.
Current system configuration
Firewall is active
Intrusion Prevention is inactive
Web Filtering is active
Network Visibility is active, 18 Application Control rules active
FTP Proxy is inactive
SMTP Proxy is active
POP3 Proxy is inactive
Web Application Firewall is active
Antivirus is active for protocols HTTP/S, SMTP, WAF
AntiSpam is active for protocols SMTP
AntiSpyware is active
Email Encryption is inactive
Site2Site VPN is inactive
Remote Access is active
HA/Cluster is inactive
Endpoint Protection is active
Wireless Protection is active
the big ram eater is the http proxy..the ips also has issues. Combine the two and it's disastrous. You are only using ips and minor things so your config is fine. turn on http proxy though and your box will fall over..your 150 users will think they are on dialup if they can get to the net at all.
__________________
Owner: Emmanuel Technology Consulting
http://www.etc-md.com
Sophos Silver Solution Reseller
Sophos Certified Architect - UTM
Gillware Data Recovery Afilliate
MIcrosoft Registered Partner
Reply With Quote
Member
Join Date: Nov 2012
Posts: 62
#134 (permalink)  
Old 01-10-2013, 04:43 AM
Default

Quote:
Originally Posted by William View Post
the big ram eater is the http proxy..the ips also has issues. Combine the two and it's disastrous. You are only using ips and minor things so your config is fine. turn on http proxy though and your box will fall over..your 150 users will think they are on dialup if they can get to the net at all.
Web Filtering = httpproxy
Reply With Quote
Wizard
Join Date: May 2003
Location: Brunswick, Maryland, USA
Posts: 5,241
#135 (permalink)  
Old 01-10-2013, 04:47 AM
Default

what kind of swap are you using? you can't tell that form the webadmin since that's been hidden now. hit the shell type free for a quick look.
__________________
Owner: Emmanuel Technology Consulting
http://www.etc-md.com
Sophos Silver Solution Reseller
Sophos Certified Architect - UTM
Gillware Data Recovery Afilliate
MIcrosoft Registered Partner
Reply With Quote
Sascha Paris's Avatar
Senior Member
Join Date: Jun 2008
Location: Switzerland
Posts: 487
#136 (permalink)  
Old 01-10-2013, 05:10 AM
Default

Quote:
Originally Posted by William View Post
what kind of swap are you using? you can't tell that form the webadmin since that's been hidden now. hit the shell type free for a quick look.
...and you still find swap under reporting&logs / hardware graphs ;o) It's only hidden in the dashboard.
__________________
I love to post this Link everywhere in this forum: http://www.astaro.org/gateway-produc...-tweaking.html
Reply With Quote
Member
Join Date: Jan 2012
Posts: 64
#137 (permalink)  
Old 01-10-2013, 02:18 PM
Default

It sure is odd for them to go out of their way to remove it from the dashboard...
Reply With Quote
Senior Member
Join Date: Dec 2005
Location: Switzerland
Posts: 117
#138 (permalink)  
Old 01-16-2013, 01:39 PM
Default

I received mail from Sophos support, because of the memory leak with 9.004-34.
They told me to change the primary scan engine from Sophos to Avira and restart http-proxy.
After executing this, the swap-usage on our ASG320 went down from over 90% to actual 61%.

Further Sophos support told me, that 9.005 should arrive at thursday, next week (24th of january)
__________________
@Work (productive):
2 x ASG 320 rev.4, HA, 9.006-5
9 x RED-10
6 x AP-50
6 x AP-30
1 x AP-10
10 sites
- HTTP Proxy / SMTP Proxy / IPS / Dual Antivirus / Antispam / SSL VPNs / IPSec VPNs / Mail encryption

@Work (testlab):
3 x 9.006-5 VM Cluster running on ESX 5.0
Reply With Quote
Wizard
Join Date: May 2003
Location: Brunswick, Maryland, USA
Posts: 5,241
#139 (permalink)  
Old 01-16-2013, 02:05 PM
Default

61% is still too high for a properly tuned/setup Linux system...but that is an improvement.
__________________
Owner: Emmanuel Technology Consulting
http://www.etc-md.com
Sophos Silver Solution Reseller
Sophos Certified Architect - UTM
Gillware Data Recovery Afilliate
MIcrosoft Registered Partner
Reply With Quote
wingman's Avatar
Super Moderator
Join Date: Feb 2009
Location: In a galaxy far far away
Posts: 3,518
#140 (permalink)  
Old 01-16-2013, 03:02 PM
Default

Quote:
Originally Posted by Copyright View Post
I received mail from Sophos support, because of the memory leak with 9.004-34.
They told me to change the primary scan engine from Sophos to Avira and restart http-proxy.
After executing this, the swap-usage on our ASG320 went down from over 90% to actual 61%.

Further Sophos support told me, that 9.005 should arrive at thursday, next week (24th of january)
I have single scan engine selected with Avira antivirus and the Swap went down only when I've disabled IPS. When both IPS and proxy are enabled ,the swap continues to grow. Is there another way to ensure that the primary scan engine is Avira but both are being in use?
__________________

Astaro ASG 120 Rev. 4 |Version 9.0** |1 X Astaro wireless AP10
Sophos UTM 120 Rev. 5 |Version 9.1** | 2 X Astaro wireless AP10
GPG Key Fingerprint: B205 ED94 FBF0 E617 63A5 C6C9 D15D 70A1 B84E 9AC9
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT. The time now is 05:28 AM.


Powered by vBulletin® Version 3.8.6
Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.

These pages are specifically maintained for the discussion of firewall issues within the Open Source community, and might already reflect new alpha/beta releases under development. Please refer to our product specifications for the functionality of the actual release. Discussions of new/enhanced functionality does not constitute a commitment of Astaro, to integrate this functionality into future releases.