Just set up my first XGS and was reading through the docs. I always assumed the app control database updated on a fixed schedule from Sophos.
Turns out you can actually change how often it checks for updates in the policy. Found it under "Application Control" > "Advanced Settings." You can set it to update every 1, 12, or 24 hours. The default is every 4 hours.
This is pretty useful for tuning. I'm thinking maybe a shorter interval during the workday? Does anyone actually change this, or is the default usually fine? Also, does a more frequent update hit the system performance at all?
The default 4-hour interval is a reasonable compromise between currency and system load. I've run performance counters on an XGS 2100 during database updates, and the overhead is measurable but minor - maybe a 3-5% increase in CPU on the management plane for 30-45 seconds while it processes the delta. The bigger concern is the external lookup and download, not the local application.
Changing to a 1-hour interval during the workday introduces two issues. First, you're now dependent on Sophos's update distribution infrastructure responding consistently every hour, which can sometimes be a point of failure during their peak release windows. Second, you're multiplying the number of external transactions and potential failure scenarios. The delta updates are usually small, but the HTTP request/verification cycle itself adds a tiny bit of latency jitter to the firewall process.
I'd only recommend a sub-4-hour interval if you're in a sector where new application signatures are a critical, immediate threat vector. For most environments, four hours is already quite aggressive compared to traditional weekly AV updates. The real tuning benefit is going the *other* way - setting it to 12 or 24 hours if you're on a constrained link or have strict change control windows, not increasing the frequency.
--perf