121
Zenarmor (Sensei) / Re: Sensei not starting
« on: October 16, 2021, 02:13:44 pm »
Hmm, HW looks good as far as I can tell. Did you install all Sensei/Zenarmor packages in OPNsense's plugins section?
This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.
Hi @athurdent,
It's our pleasure. I hope you are liking it so far.
Yes, MAC addresses have been introduced to Policies and Reporting. Not yet for bypassing the traffic. A bit of information there:
The reason you're still seeing CPU activity even though you've bypassed an IP address is that it still hits the packet engine.
Although the engine does not apply packet inspection and/or filtering etc, netmap still has to process it, deliver it to the zenarmor engine and re-transmit it to the network stack. This sometimes might be another bottleneck.
@athurdent
Do you think SR-IOV also helps if host (virtualized env. platform) uses vSwitches ?
I work with ESXi hosts where a NIC goes directly to vSwitch and so the NIC seems not to be "sliced" for VM guests.
Thanks for the benchmarks btw.
T.