I have the same chip and I get 3Gbps MAX out of a 10Gb connection so it may just be the chip though its a fast chip...old.
This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.
Show posts MenuQuote from: terry274 on August 07, 2023, 03:28:46 PM
I have leases marked abandoned that I can't delete. I don't know why. They are set to expire, so I believe they will go away then.
Quote from: sepahewe on May 23, 2022, 07:11:57 PM
Hi,
I tried enabling RSS and Suricata works. Better spread of CPU load and better performance. However, haproxy runs into issues. HAProxy can't connect to anything, not for health checks and not for live traffic. Based on earlier comment on so_reuseport, I changed my config to simple binds and enabled noreuseport for haproxy, but haproxy still fails to connect.
It gets very sporadic, ~10%, successes but that's rare enough for a health check not to clear. Since I have 8 RSS queues it is almost like haproxy only gets traffic from 1 queue which would amount to 12.5% success.
I have an X520 (ix) and that does not support RSS to my knowledge. running this will confirm:
sysctl dev.ix | grep rss
No results means driver/nic is unsupported, mine returns nothing.
I've tried all combos of net.inet.rss.enable, noreuseport, with health checks, w/o health checks and success/failure depends completely on net.inet.rss.enable. The error reported from haproxy is "Layer4 timeout"
driver: ix
NIC: Intel D-1500 soc 10 gbe, (X552)
Opnsense: 22.1.7_1
I more than happy to help testing but would appreciate any suggestions in what direction to start.