Quote from: Quetschwalze on August 23, 2020, 09:31:17 amTested with igb interfaces and pppoe on wan (removed VLAN for testing)Suricata seems to start fine:....However, it doesn't alert or block on anything.Then I tried Sensei on the WAN Interface. It starts, but afterwards Internet is gone. Reports do not show any sessions or blocks.Hi @Quetschwalze, thanks. Any chances that you can also send a pcap trace? - Sensei is not meant for WAN right now.
Tested with igb interfaces and pppoe on wan (removed VLAN for testing)Suricata seems to start fine:....However, it doesn't alert or block on anything.Then I tried Sensei on the WAN Interface. It starts, but afterwards Internet is gone. Reports do not show any sessions or blocks.
Yes, No Problem. Just to make sure, you'll need a pcap of suricata/pppoe wan interface traffic?
Hi @scream, are you doing the tests with speedtest.net ? If so, can you repeat the test with scp ? Try scp'ing a (large) file to one of the IP addresses on sensei protected interfaces on the firewall (you'll basically copy a file to the firewall.) Run this test with and without sensei and see how much it differs. e.g. scp 1gbfile root@fw-sensei-protected-interface-ip:/dev/null
@scream, thanks. that looks interesting. let us try to reproduce this here. currently we can attain 450-500 Mbps with or without sensei in our lab.
It is mostly related to the kernel. I would not expect 1.6 would do any difference. What happens if you put sensei into bypass mode?
20.1.9 sensei bypass mode => 855 Mbit/s 20.7 sensei bypass mode => 205 Mbit/sNote that there is now some other traffic in the networks so 855 Mbit/s is normal.https://paste.ubuntu.com/p/35v3HxmJrT/
Any chances that you can reach out? Send a PR via "Report Bug" menu on the upper right hand side of the screen. We would like to have a closer look.
# fetch https://updates.sunnyvalley.io/opnsense/updates/netmap-kernel/os-sensei-1.6.beta1.txzos-sensei-1.6.beta1.txz 25 MB 4688 kBps 05s# pkg add os-sensei-1.6.beta1.txz
Hi @scream,Sure, please find it below Code: [Select]# fetch https://updates.sunnyvalley.io/opnsense/updates/netmap-kernel/os-sensei-1.6.beta1.txzos-sensei-1.6.beta1.txz 25 MB 4688 kBps 05s# pkg add os-sensei-1.6.beta1.txz Please be noted, although this has been thoroughly tested and reached beta stage, it's still not meant for production use. Use carefully.