16
20.7 Legacy Series / Re: repeat crashing
« on: November 09, 2020, 11:42:04 am »Sensei or Suricata enabled?
hey, why did you ask ?
This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.
Sensei or Suricata enabled?
Sensei or Suricata enabled?
Think i cracked the problem.
core issue
1) dhcp scope did have a gateway set but not a router
2) manually setting dhcp option 3 to type IP and the ip address for the LAN interface appears to work
depending issues
1) IDS crash on rule update fail = to all appearances, is fixed now (crash because of DNS fail !)
2) unbound flapping = improvement, not fixed
Yes, I could have deployed test instance of OPNsense. But before doing so, I would like to know what to expect and which way is better one
By slow I mean a drop from 1.95Gbs to 0.915Gbs, 50% reduction.
In 20.1.x I was seeing about 1.7Gbs, so much less drop when netmap enabled.
I only showed the Suricata on LAN. I'll re-run with sensei normal and bypass more and send the results. By the way, my ELK stack is on another ESXI with a 10Gbs link, so the ELK CPU/Memory load will not impact opnsense/sensei.