OPNsense Forum

English Forums => Zenarmor (Sensei) => Topic started by: actionhenkt on July 31, 2021, 05:03:51 pm

Title: exclude IP from sensei
Post by: actionhenkt on July 31, 2021, 05:03:51 pm
Hi,

Sensei is using 100% cpu and is capping my throughput, is it possible to exclude an IP in sensei so sensei does not scan the traffic at all ?
Have added the IP to the exempted network/ip list but sensei is still scanning.
Title: Re: exclude IP from sensei
Post by: mb on July 31, 2021, 05:43:39 pm
hi @actionhenkt, exempted networks/ip is the way to go.

Is this new (e.g. started after upgrade to 21.7) or has this been an ongoing situation?
Title: Re: exclude IP from sensei
Post by: actionhenkt on July 31, 2021, 07:50:13 pm
Thanks, I already added the IP's but im not sure if this also works to/from external destinations/sources ? When downloading/uploading, with sensei on the max download/upload is around 330/340 mbps, without sensei I get 940mbps.

The issue is not new also had this pre 21.7 just trying to work around it without disabling sensei
Title: Re: exclude IP from sensei
Post by: mb on July 31, 2021, 11:01:29 pm
What happens if you put sensei onto bypass mode? In the bypass mode, sensei will be just forwarding packets back and forth.
Title: Re: exclude IP from sensei
Post by: actionhenkt on August 01, 2021, 11:43:16 am
setting bypass mode did not make a difference
Title: Re: exclude IP from sensei
Post by: mb on August 01, 2021, 06:05:35 pm
Got it. Looks like netmap. Can you send a bug-report? Let's have a look at your ethernet drivers & configuration.
Title: Re: exclude IP from sensei
Post by: almodovaris on August 06, 2021, 09:33:30 am
I have an APU2 and Sensei is in bridge mode. I have whitelisted:

news.eweka.nl
sslreader.eweka.nl
81.171.92.0/24

But Sensei keeps scanning the connection, using one core of the processor above 90%.
Title: Re: exclude IP from sensei
Post by: almodovaris on August 06, 2021, 10:11:12 am
When I download the whitelist, it is empty (0 bytes).
Title: Re: exclude IP from sensei
Post by: almodovaris on August 19, 2021, 03:19:59 pm
There is a difference between allow connection, but inspect it and do not inspect at all the connection. I am afraid whitelist does the former rather than the later.