Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Messages - runo10

#1
Quote from: BrandyWine on December 22, 2025, 12:13:03 AMTurn off / disable all the power stuff. Why is that even needed?
What a wonderfull idea :) You must be smartest guy in your school.
#2
Quote from: runo10 on September 17, 2026, 11:03:59 AMI didnt check for issue one but I have issue 2. When I enable suricata, a few minutes later all network gone. And later a few minutes it start to work again but it gones again a minutes later. This repeats continuesly.
I have crowdsec and suricata. But it worked before may be latest updates break something.

Also when I check suricata alerts from gui there is no alerts?

I find a side solution, If someone needs. I use divert mode with no problem. Probably problem related to netmap.
#3
I didnt check for issue one but I have issue 2. When I enable suricata, a few minutes later all network gone. And later a few minutes it start to work again but it gones again a minutes later. This repeats continuesly.
I have crowdsec and suricata. But it worked before may be latest updates break something.

Also when I check suricata alerts from gui there is no alerts?
#4
I dont have any proxy. Can be a bug on opnsense side?
#5
Quote from: Monviech (Cedrik) on May 12, 2026, 03:09:15 PMIt worked fine before what?

What changed that made it not work? Did you update? What was your last version, what your current version.

Give some more info please.
Nothing changed.

Current Version   25.7.11_9
#6
why you dont recommend?

Thats problem not setup related. About traffic graph. It was working before.
#7
yes it looks reverse now.

That ip makes scraping so all traffic comes from wan -> bridge -> lan
#8
there is traffic that comes from wan interface to bridge , it looks like Lan in. But it is not. It was working properly before now there is a problem.

Also traffic that comes from lan servers looks like wan out.

it must show reverse, wan in and lan out.
#9
General Discussion / Traffic Graph looks reversed
May 12, 2026, 12:39:35 PM
It was normal but now it shows coming traffic from wan  as lan in, and lan traffic as wan out

#10
Hello,

I have a r210 II-1240v2 server as a opnsense firewall with "Intel(R) I350 (Copper)" ethernet card. I use transparent bridge mode
I have got packet loss problems.
I have tried many things.

I make all offloads disabled and this tunables:
dev.igb.0.eee_disabled 1
dev.igb.0.fc 0
net.isr.bindthreads 1
hw.igb.tx_process_limit -1
hw.igb.rx_process_limit -1
net.isr.dispatch deferred 
net.link.bridge.pfil_onlyip 1
net.inet.udp.checksum 1
net.inet.tcp.tso 0
No hardware acceleration

That settings not worked much. I have tried these and it is much better now nearly solved:

all interfaces mtu 1450, mss 1412
firewall normalization-> mss clamping 1410
use powerd and maximum setting for all
dev.igb.0.eee_control 0
hw.igb.enable_aim 0
legal.intel_igb.license_ack 1
 
But it gives 1-2/1000request timeouts(timeout threshold 5sec) in country network. (https request)

And it gives nearly 1 ssl connect error on global network per hour at better stack(uptime checker)(https request)


And gives no error for ping requests at global network for now.
Any idea?
#11
It was 60k pps, I thought granularity(1 minute) is base time. I have closed ips mode and I use a script to inspect logs and block ips via firewall. Now cpu usage looks better. May handle 300k-500k pps
#12
Quote from: pfry on October 25, 2025, 03:29:43 PM
Quote from: runo10 on October 25, 2025, 06:08:10 AM[...]
Actually these are default rulesets thats available on download page. I select most of them.[...]

Ah, IPS rules. Thanks - I should have figured that out. It's been a while since I (actively) used an IPS - they keep growing...


Do you have suggestion? Also I want to block ips on firewall that droped by suricata
#13
Quote from: BrandyWine on October 25, 2025, 09:01:50 AMWhat does this fw do?
Load seems high. Why not press SHIFT+P and then take pic? 1.87 is not terrible for that xeon, but you need to look at each core usage, my guess is cpu0 is probably pegged.
And you are very close to swap when you took that pic, maybe watch 'vmstat 1' for a bit?

Does this fw have hyperT disabled?

I use this firewall only for instrusion detection. May be I select many rules but pps is very low. HyperThread is enabled.

#14
Quote from: BrandyWine on October 25, 2025, 07:05:19 AMI prefer the load averages as seen at the top of top.

SHIFT P

Pic that down to the 1st PID


#15
Quote from: BrandyWine on October 25, 2025, 06:23:31 AM
Quote from: runo10 on October 25, 2025, 06:08:10 AMI couldnt find a settings for suricata core usage.

SSH on in, run 'top'
Suricata is sure to be at top of the list.

Which version of OPNsense are you running?


I look wrong by the way. It is 60k per minute. 1k pps is very low I think. Version is 25.7.6. This cpu usage means suricata using one core?