OPNsense Forum

Archive => 22.7 Legacy Series => Topic started by: seed on October 29, 2022, 06:30:51 PM

Title: Performance Documentation Suricata
Post by: seed on October 29, 2022, 06:30:51 PM
Is this still current?

https://docs.opnsense.org/troubleshooting/performance.html


QuoteNote regarding IPS

When Suricata is running in IPS mode, Netmap is utilized to fetch packets off the line for inspection. By default, OPNsense has configured Suricata in such a way that the packet which has passed inspection will be re-injected into the host networking stack for routing/firewalling purposes. The current Suricata/Netmap implementation limits this re-injection to one thread only. Work is underway to address this issue since the new Netmap API (V14+) is now capable of increasing this thread count. Until then, no benefit is gained from RSS when using IPS.