OPNsense Forum

English Forums => Intrusion Detection and Prevention => Topic started by: Braineh on February 25, 2024, 09:00:19 am

Title: Suricata cutting download speed if IPS enabled
Post by: Braineh on February 25, 2024, 09:00:19 am
Hallo everyone.

I'm quite new to Opnsense and got a question about Suricata. I registered for the ET telemetry edition, saved the token, enabled rules and downloaded them. Afterwards, I enabled Suricata and also IPS. What confuses me is, that enabling IPS is cutting my download speed by a minimum of 50%, while disabling it restores it to full speed. But here I can't see the point as the traffic is checked but not blocked without IPS anyway, so I can't see why this would cut the download performance that hard.
Anyone?
Thanks in advance.
Braineh
Title: Re: Suricata cutting download speed if IPS enabled
Post by: cookiemonster on February 26, 2024, 12:51:47 am
yes, that is the normal behaviour, in that there is a high performance penalty from IPS. It is more of factor with CPUs with lower single thread performance.
Title: Re: Suricata cutting download speed if IPS enabled
Post by: johnmcallister on February 26, 2024, 02:56:25 am
....But here I can't see the point as the traffic is checked but not blocked without IPS anyway, so I can't see why this would cut the download performance that hard.

What is the make,  model, & specifications (RAM amount, CPU speed, # of CPU cores, etc.) of the hardware your OPNsense instance (router) is running on?

What is the bandwidth of your internet connection, in Mbps or Gbps per second?  Fiber? Cable? Which provider?
Title: Re: Suricata cutting download speed if IPS enabled
Post by: Braineh on March 01, 2024, 11:33:35 am
It's an Intel Celeron quad core mini itx board, 16 GB memory. From what I see, the CPU peaks at max 70% when log on but goes down instantly, during traffic it's never above 50%.

Provider is o2 and it's working through 4G / 5G since we unfortunately still got no serious wired connection here. Usually I get 100-250 MBit here. On the WAN side (Realtek) sits a ZTE 5G Router using bridge mode. On LAN side there's a Intel NIC, forgot which one I used in there. All Hardware acceleration / offload is disabled
Title: Re: Suricata cutting download speed if IPS enabled
Post by: Enoch58 on April 23, 2024, 12:35:58 pm
Yes, that's the typical behavior, where (https://cannacraftcorner.com) there's a significant performance penalty from IPS. This is more (https://pureplantpleasures.com) pronounced with CPUs that have lower single-thread performance.