OPNsense
  • Home
  • Help
  • Search
  • Login
  • Register

  • OPNsense Forum »
  • English Forums »
  • Intrusion Detection and Prevention »
  • Disable all hardware offloading - VLAN Hardware Filtering
« previous next »
  • Print
Pages: [1]

Author Topic: Disable all hardware offloading - VLAN Hardware Filtering  (Read 8361 times)

dreamerman

  • Jr. Member
  • **
  • Posts: 59
  • Karma: 1
    • View Profile
Disable all hardware offloading - VLAN Hardware Filtering
« on: January 01, 2019, 12:25:27 am »
Hi, I am following the awesome post by elektroinside on setting up IDS/IPS. In regards to hardware offloading, I am not sure which option I should select for VLAN Hardware Filtering- enable/disable/leave default.
Not sure if my understanding is correct -  enable means the NIC is doing the work and disable means the software is doing the work (ie higher CPU overheads).
Please help?
Logged
NEXCOM DNA120 aka Sophos SG115 | Intel Atom E3827 Bay Trail Dual Core 1.7GHz | 4GB DDR3 | 64GB SSD

bartjsmit

  • Hero Member
  • *****
  • Posts: 2023
  • Karma: 194
    • View Profile
Re: Disable all hardware offloading - VLAN Hardware Filtering
« Reply #1 on: January 01, 2019, 09:32:36 am »
Hardware filtering or any other type of offload lets the CPU do less work when enabled by performing operations in dedicated silicon (usually an ASIC).

Bart...
Logged

dreamerman

  • Jr. Member
  • **
  • Posts: 59
  • Karma: 1
    • View Profile
Re: Disable all hardware offloading - VLAN Hardware Filtering
« Reply #2 on: January 01, 2019, 12:32:18 pm »
Quote from: bartjsmit on January 01, 2019, 09:32:36 am
Hardware filtering or any other type of offload lets the CPU do less work when enabled by performing operations in dedicated silicon (usually an ASIC).
Thanks Bart but I am still not sure if I should disable VLAN Hardware Filtering to setup IDS/IPS. I think this is enabled by default.
Logged
NEXCOM DNA120 aka Sophos SG115 | Intel Atom E3827 Bay Trail Dual Core 1.7GHz | 4GB DDR3 | 64GB SSD

bartjsmit

  • Hero Member
  • *****
  • Posts: 2023
  • Karma: 194
    • View Profile
Re: Disable all hardware offloading - VLAN Hardware Filtering
« Reply #3 on: January 01, 2019, 12:34:42 pm »
I would leave it enabled - IDS/IPS and VPN are workloads that are most capable of limiting the throughput of the firewall. The more streamlined, the better.

Bart...
Logged

dreamerman

  • Jr. Member
  • **
  • Posts: 59
  • Karma: 1
    • View Profile
Re: Disable all hardware offloading - VLAN Hardware Filtering
« Reply #4 on: January 01, 2019, 01:20:31 pm »
Thanks Bart!
Logged
NEXCOM DNA120 aka Sophos SG115 | Intel Atom E3827 Bay Trail Dual Core 1.7GHz | 4GB DDR3 | 64GB SSD

  • Print
Pages: [1]
« previous next »
  • OPNsense Forum »
  • English Forums »
  • Intrusion Detection and Prevention »
  • Disable all hardware offloading - VLAN Hardware Filtering
 

OPNsense is an OSS project © Deciso B.V. 2015 - 2024 All rights reserved
  • SMF 2.0.19 | SMF © 2021, Simple Machines
    Privacy Policy
    | XHTML | RSS | WAP2