Call for testing: New netmap enabled kernel

Started by mb, February 06, 2019, 12:21:44 AM

Previous topic - Next topic
Should I take my performance issue to another topic?


at this point, I'm not running *ANY* IPS (I want to at some point, but I'd like to get the raw performance back to the ~900Meg).

Well, the thread here is about netmap which is used in IPS and Sensei only. The IPS performance thread is about IPS performance first and foremost, but offers sysctl tweaks to the driver which are not necessarily specific to IPS.


Cheers,
Franco

It does help...
see my reply over there.

Download side is still meh, but the upload side is *MUCH* improved.


Hi franco,

QuoteThere's one commit we don't have yet which would suggest a considerable speedup in the IPS department, however:

https://svnweb.freebsd.org/base?view=revision&revision=345269

What remains to be seen is if this requires changes to Suricata to make use of the speedup potential.

Yep, this requires a little work since API is changed for this purpose.

any news on 19.1.5 version of a netmap kernel?

There is no 19.1.5 kernel so there won't be a 19.1.5 netmap kernel. ;)


Cheers,
Franco

Will there be a 19.1.7-netmap kernel?

Greetings,
Christian

The kernel only had two patches (one possible kernel panic bug, one possible security issue). I might respin next week, but for now I cannot prioritise.


Cheers,
Franco

Thanks anyway, Franco. I also look @ netmap because of vlans and Sensei.
Proxmox enthusiast @home, bare metal @work.

So since there was no new kernel in 19.1.7 and 19.1.8 that means I need to install the new netmap via CLI correct? The netmap in plugins is still old?

Hi @spetrillo,

If you're not using virtio ethernet, you do not need to use new netmap kernel for now.

New netmap code is intended to make the netmap infrastructure more stable & robust. Though, there are a few issues that need to be addressed with the new kernel.

A new work is being planned for this. Will keep the thread posted.

The new netmap kernel also made it possible to use Suricata on an interface with multiple VLANs in Promiscous Mode in IPS mode.
Without the netmap kernel all traffic stops as soon as suricata starts.

At least I tought it was the kernel.

Gesendet von meinem MI 9 mit Tapatalk