1
Hardware and Performance / Re: Simple L3 traffic flood leads to CPU denial of service
« on: March 25, 2023, 07:49:23 pm »
I could find the main culprit and greatly improve the performance :
1. Syslog was the process taking much CPU : I was not aware of a system parameter that enabled logging for default rules, NAT, etc. I was not aware of that because I did not enable logging in my rules.
2. This performance setting was also a game changer : https://docs.opnsense.org/troubleshooting/performance.html#receive-side-scaling
CPU charge is much better controlled now.
I am still experienced some dropped session, so still have some improvements to do, but it's much, much better !
1. Syslog was the process taking much CPU : I was not aware of a system parameter that enabled logging for default rules, NAT, etc. I was not aware of that because I did not enable logging in my rules.
2. This performance setting was also a game changer : https://docs.opnsense.org/troubleshooting/performance.html#receive-side-scaling
CPU charge is much better controlled now.
I am still experienced some dropped session, so still have some improvements to do, but it's much, much better !