Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Messages - sanscorp

#1
I'm running VMware on a dedicated HP workstation (Z420) with 128GB of mem and an older (single) Xeon E5-2650 (V0) @2.0GHz. OPNsense is running on 4 cores 4 threads but recently I learned most processes are single core services/processes. OPNsense has "priority" over other VM's and the CPU has an 6GHz reservation (total capacity: 15.96 GHz).

With fiber 1000/1000 I only get 200-300 Mbps with Suricata on (IDS/IPS) no matter which interface or Pattern matcher I use.

When I disable IDS/IPS completely I get a rather consisten 925/935 Mbps on speedtest.net but CPU rises to 100% during the "full speed load".
I'd rather use IDS/IPS (obviously) for security reasons but am not willing to sacrifice 600 Mpbs.

First question:
I know my setup is rather old but I'm not in the position to buy new hardware.
What would be the optimum config for me regarding vCPU's and memory allocation for OPNsense with ADguard as DNS server?

Second question:
After optimising the vCPU, what would be the correct OPNsense config to make the most of the multicore/multithread vCPU?


Thank you in advance!
#2
General Discussion / Re: Maltrail on Opnsense
June 20, 2022, 09:04:16 AM
Can someone please explain how to auto block the maltrail detections?
As an absolute beginner it is hard to find some info on this subject.

Few questions:
Is an alias just a name for a group to keep it manageable?
I do see an auto generated alias named "BlocklistMaltrail" but it does not contain any addresses.

It would be nice to only auto block medium and high security threads.
Running OPNsense version 22.1.8_1 and Mailtrail version 1.8

Thanks!
#3
Obviously.

How do I mount it as read write? I do not want to use the install media to recover a lost password.

I have gained access now, trough the history function of bitwarden, but it would be nice to know for the next time.
#4
I followed those instructions in the first place :)
#5
I'm trying to reset the root password via Single user mode but I get a read only error when following the tutorial.
Bitwarden messed up, synced wrong and now I need to reset my password.

Root is also "disabled" via the system --> access --> users panel.
When I try a reset of my other (main) user I also get the error that the file system is read only.

The system is up-to-date.
What is the correct procedure here?

Thank you in advance!