OPNsense
  • Home
  • Help
  • Search
  • Login
  • Register

  • OPNsense Forum »
  • Archive »
  • 20.7 Legacy Series »
  • Call for testing: official netmap kernel
« previous next »
  • Print
Pages: [1] 2 3 ... 7

Author Topic: Call for testing: official netmap kernel  (Read 38639 times)

mb

  • Hero Member
  • *****
  • Posts: 914
  • Karma: 97
    • View Profile
    • Sunny Valley Networks
Call for testing: official netmap kernel
« on: September 16, 2020, 06:53:51 pm »
Dear OPNsense community,

It's my pleasure to announce that OPNsense team has shipped the official netmap test kernel today.

This kernel fixes important stability and reliability issues with regard to vmx(4), vtnet(4), ixl(4), ix(4) and em(4) ethernet drivers.

The  kernel also adds long-awaited support for tun(4) and lagg(4) interfaces.

The end benefit of this kernel is that you'll be able to run Sensei or Suricata on the following:
  • OpenVPN and other VPNs which use tun(4) interface
  • Link Aggregation Groups (lagg)
  • QEMU/KVM guests with performant vtnet driver
  • VMware guests with vmx driver
  • Intel 10 Gbps Ethernet drivers
  • Intel 1 Gbps Ethernet (em driver) with VLANs

To deploy the new kernel just run below command and restart your firewall.

Code: [Select]
# opnsense-update -kr 20.7.3-netmap
Patches which went into this kernel have been under heavy testing by us (Sunny Valley Networks) and by the OPNsense team for a few weeks now.

We'd very much appreciate your further testing and feedback. If no further issues pop up, OPNsense team will be shipping all these functionality with 20.7.4 or later releases.

As Sunny Valley Networks, we'd very much like to thank OPNsense/HardenedBSD team, netmap team (Universita di Pisa) and the FreeBSD team for their awesome collaboration and precious efforts. With their full coordination and co-operation, we are able to provide this today.
« Last Edit: September 25, 2020, 04:11:08 pm by mb »
Logged

mimugmail

  • Hero Member
  • *****
  • Posts: 6299
  • Karma: 434
    • View Profile
Re: Call for testing: official netmap kernel
« Reply #1 on: September 16, 2020, 09:44:01 pm »
Good news! Today in Webinar I was asked about vmx driver status. Thanks for your efforts!! :)
Logged
Twitter: mimu_muc
WWW: www.routerperformance.net
Support plans: https://www.max-it.de/en/it-services/opnsense/
Commercial Plugins (German): https://opnsense.max-it.de/

mb

  • Hero Member
  • *****
  • Posts: 914
  • Karma: 97
    • View Profile
    • Sunny Valley Networks
Re: Call for testing: official netmap kernel
« Reply #2 on: September 16, 2020, 09:46:04 pm »
All welcome @mimugmail. Enjoy ;)
Logged

andrema2

  • Jr. Member
  • **
  • Posts: 86
  • Karma: 3
    • View Profile
Re: Call for testing: official netmap kernel
« Reply #3 on: September 16, 2020, 09:59:27 pm »
Quote from: mb on September 16, 2020, 06:53:51 pm
# opnsense-update -kr 20.7.2-netmap

Just one question, maybe a silly one, is this reversable in case of problems ?

Thanks
Logged

binaryanomaly

  • Full Member
  • ***
  • Posts: 139
  • Karma: 9
    • View Profile
Re: Call for testing: official netmap kernel
« Reply #4 on: September 16, 2020, 10:34:26 pm »
Awesome!
Logged

mb

  • Hero Member
  • *****
  • Posts: 914
  • Karma: 97
    • View Profile
    • Sunny Valley Networks
Re: Call for testing: official netmap kernel
« Reply #5 on: September 16, 2020, 10:35:40 pm »
Quote from: andrema2 on September 16, 2020, 09:59:27 pm
Just one question, maybe a silly one, is this reversable in case of problems ?

No, actually a good question. Yes, you can:

Code: [Select]
# opnsense-update -kr 20.7.2
Logged

GreenMatter

  • Full Member
  • ***
  • Posts: 126
  • Karma: 1
    • View Profile
Re: Call for testing: official netmap kernel
« Reply #6 on: September 16, 2020, 11:03:36 pm »
Quote from: andrema2 on September 16, 2020, 09:59:27 pm
Quote from: mb on September 16, 2020, 06:53:51 pm
# opnsense-update -kr 20.7.2-netmap
Just one question, maybe a silly one, is this reversable in case of problems ?
And can I apply this update directly on 20.1.9 or it's better to wait for 20.7.3?
Logged
OPNsense on:
Intel(R) Xeon(R) E-2278G CPU @ 3.40GHz (4 cores)
8 GB RAM
50 GB HDD
and plenty of vlans ;-)

binaryanomaly

  • Full Member
  • ***
  • Posts: 139
  • Karma: 9
    • View Profile
Re: Call for testing: official netmap kernel
« Reply #7 on: September 16, 2020, 11:04:07 pm »
@mb

Is it to be expected that now with "20.7.2-netmap" the update functionality proposes to update to "20.7.2"

Logged

mb

  • Hero Member
  • *****
  • Posts: 914
  • Karma: 97
    • View Profile
    • Sunny Valley Networks
Re: Call for testing: official netmap kernel
« Reply #8 on: September 16, 2020, 11:20:58 pm »
Quote from: GreenMatter on September 16, 2020, 11:03:36 pm
And can I apply this update directly on 20.1.9 or it's better to wait for 20.7.3?

Nope, this is only for 20.7.x releases.
Logged

mb

  • Hero Member
  • *****
  • Posts: 914
  • Karma: 97
    • View Profile
    • Sunny Valley Networks
Re: Call for testing: official netmap kernel
« Reply #9 on: September 16, 2020, 11:21:40 pm »
Quote from: binaryanomaly on September 16, 2020, 11:04:07 pm
Is it to be expected that now with "20.7.2-netmap" the update functionality proposes to update to "20.7.2"

Yes, that's normal. Because you're not running the standard 20.7.2 kernel.
Logged

heresjody

  • Newbie
  • *
  • Posts: 25
  • Karma: 2
    • View Profile
Re: Call for testing: official netmap kernel
« Reply #10 on: September 16, 2020, 11:22:00 pm »
Kernel update worked fine with me.

    OPNsense 20.7.2-amd64
FreeBSD 12.1-RELEASE-p9-HBSD
OpenSSL 1.1.1g 21 Apr 2020

To doublecheck I'm providing valid testing results for you (PPPoE WAN / Suricata)
1. Only select interface: In my case LAN (vtnet) and don't select WAN (vtnet vlan 6)
2. Add public IP to home networks.

Correct?
Logged

almodovaris

  • Full Member
  • ***
  • Posts: 158
  • Karma: 8
    • View Profile
Re: Call for testing: official netmap kernel
« Reply #11 on: September 16, 2020, 11:40:47 pm »
Nope, it did not change the download speed in APU2. If anything, it got even lower. I use Sensei 1.6 with September definitions.
« Last Edit: September 16, 2020, 11:45:43 pm by almodovaris »
Logged

DanMc85

  • Jr. Member
  • **
  • Posts: 68
  • Karma: 3
    • View Profile
Re: Call for testing: official netmap kernel
« Reply #12 on: September 17, 2020, 12:54:22 am »
With the new build, should Interfaces Selection for Protected Interfaces be LAN only or can I add vmx0_VLAN's and ovpns OpenVPN Server interfaces also. Wasn't sure if LAN covered them all or not.
-I do have internal DNS server running on a Domain Controller on the LAN. Not sure if that matters for config.

This is a VMWare ESXi 7 environment if the VMX didn't give it away :)
Logged

mb

  • Hero Member
  • *****
  • Posts: 914
  • Karma: 97
    • View Profile
    • Sunny Valley Networks
Re: Call for testing: official netmap kernel
« Reply #13 on: September 17, 2020, 03:18:01 am »
Quote from: heresjody on September 16, 2020, 11:22:00 pm
To doublecheck I'm providing valid testing results for you (PPPoE WAN / Suricata)
1. Only select interface: In my case LAN (vtnet) and don't select WAN (vtnet vlan 6)
2. Add public IP to home networks.

Hi @heresjody:

1- Correct. Though we have not touched pppoe+netmap yet. Use Sensei on LAN.
2- Not sure if I understood correctly. Can you elaborate?
Logged

mb

  • Hero Member
  • *****
  • Posts: 914
  • Karma: 97
    • View Profile
    • Sunny Valley Networks
Re: Call for testing: official netmap kernel
« Reply #14 on: September 17, 2020, 03:20:04 am »
Quote from: DanMc85 on September 17, 2020, 12:54:22 am
With the new build, should Interfaces Selection for Protected Interfaces be LAN only or can I add vmx0_VLAN's and ovpns OpenVPN Server interfaces also. Wasn't sure if LAN covered them all or not.
-I do have internal DNS server running on a Domain Controller on the LAN. Not sure if that matters for config.

This is a VMWare ESXi 7 environment if the VMX didn't give it away :)

:)

Yes, do not put Sensei on WAN interface; or any interface that Suricata is also running on.

Otherwise, you can add vmx parent/vlan interfaces. You can also add openvpn interfaces.

If you have an internal DNS, try the new realtime dns mapping feature ;)
Logged

  • Print
Pages: [1] 2 3 ... 7
« previous next »
  • OPNsense Forum »
  • Archive »
  • 20.7 Legacy Series »
  • Call for testing: official netmap kernel
 

OPNsense is an OSS project © Deciso B.V. 2015 - 2023 All rights reserved
  • SMF 2.0.19 | SMF © 2021, Simple Machines
    Privacy Policy
    | XHTML | RSS | WAP2