Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Messages - spaceharrier

#1
Quote from: sopex on May 23, 2026, 09:56:29 AMThe Zenarmor engine is not multi-core, so this is to be expected.

Right, just illustrating how that pans out on the 3920.
#2
I just installed a 3920 on my home 10Gbit connection, upgrading from a DEC750. Doing casual speed tests with my provider (Sonic.com) and using just my normal firewall rules the 3920 has no problem saturating the connection. Enabling Zenarmor the download speed caps at a little below 3.5Gb/s, showing about 20% CPU utilization. That's using the default policy with Moderate Control settings.

(The DEC750 couldn't fully saturate the 10Gbit connection with just firewall rules, and dropped to a little below 2Gb/s running the same Zenarmor config.)
#3
Under Interfaces -> LAN do you have Prevent Interface Removal checked? I saw what you're describing when testing failover. Shutting down the primary the VIP would move to the secondary as expected, and it would return to the primary when that host came back up. CARP status in the GUI looked correct in both states, but my ping check to the VIP started showing DUP messages as you describe. Unchecking the Prevent Interface Removal on the LAN interface solved it.

So wild guess that preventing removal is also preventing some kinds of reconfiguration.