OPNsense
  • Home
  • Help
  • Search
  • Login
  • Register

  • OPNsense Forum »
  • Profile of beyondnoyeb »
  • Show Posts »
  • Topics
  • Profile Info
    • Summary
    • Show Stats
    • Show Posts...
      • Messages
      • Topics
      • Attachments

Show Posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

  • Messages
  • Topics
  • Attachments

Topics - beyondnoyeb

Pages: [1]
1
Hardware and Performance / mellanox connectx-3 lan ips issues...
« on: June 08, 2020, 05:35:29 pm »
Hey all,

Added in a mellanox connectx-3 into the mix and followed mimugmail's excellent guide for updating the firmware off the get go.  I'm running into a bit of a strange issue however; I've realized that if I have IPS turned on the LAN interface (promiscuous mode on) I lose ability to access anything across vlan's or out on the net.  I can access the LAN interface of opnsense, but that's it...

The method I went through to install / move vlans and Lan interface over:
Installed card
Added mlx4en_load="YES" to the /boot/loader.conf.local
Upgraded firmware
Went into interfaces / other types / vlans and changed the all of the vlan's over to interface mlxen0
Went to interfaces / assignments and changed LAN over to mlxen0
inserted cable, interface up.

Things I've tried for the hell of it; turned off promiscuous mode and that killed all connections; so I know that's not a fix ;). 

Does anyone use these cards with IPS turned on and have vlans?  I feel like i'm missing something simple here or that my method for moving the interfaces over wasn't right.   IPS was working fine when I was over on the copper gigabit Intel 350 NIC.

For the time being i've turned off IPS Mode but would like to have it back on for my LAN as I find it incredibly useful.

Thanks in advance for any guidance you can offer. 

EDIT: MODS: just realized I might should have put this in the IPS forum, please feel free to move it if so

2
Hardware and Performance / Question on expected performance of setup
« on: May 19, 2020, 05:32:02 pm »
Hey all,

Been using opnsense for a few months now and am absolutely in love.  With that said, I am trying to best tune my environment for performance and seem to be hitting some issues. 

Setup:  (this is an older box I am repurposing)
CPU: i7-3770
Memory: 32gb
Nic: Intel i350-t4
opnsense: 20.1.6
VLANs: 4

I have made all changes listed in the sticky thread regarding intel nic tuning

Test Case 1) Without things like netflow (insights), suricata, and GeoIP I can saturate my Verizon fios 940/880. 
Test Case 2) Netflow / Suricata (19,000 rules set to drop, monitoring WAN and LAN interfaces) / GeoIP  my speeds are dropping down to 400/400.
Test Case 3) Netflow / Suricata GeoIP running but Suricata ONLY monitoring WAN, I can manage to get it back up to 800/800.

During the testing, I can see suricata is definitely using up all 8 threads on the cpu (750-780% CPU usage) via top in test case 2.  This drops down to 300-400% CPU usage in test case 3.

Is this CPU / older box simply too old to run at line rate?  I don't mind investing in a newer gen; I just want to make sure that a newer gen xeon type setup will run at the full line rate with everything turned on (monitoring WAN and LAN).

Thanks!


Pages: [1]
OPNsense is an OSS project © Deciso B.V. 2015 - 2024 All rights reserved
  • SMF 2.0.19 | SMF © 2021, Simple Machines
    Privacy Policy
    | XHTML | RSS | WAP2