are you running Suricata and Sensei on the same interface? It seems that Suricata is crashing and that is causing your gateway monitoring to flap, can you include logs from Suricata?
That looks ok, I am wondering if you can include the logs when IDS fails, It seems that it is running successfully.
hi @klamathOPNsense 21.7.3_3-amd64FreeBSD 12.1-RELEASE-p20-HBSDOpenSSL 1.1.1l 24 Aug 2021Hardware: Dell R720CPU 1 Intel(R) Xeon(R) CPU E5-2650 v2 @ 2.60GHz Model 62 Stepping 4 2600 MHz 8coreCPU 2 Intel(R) Xeon(R) CPU E5-2650 v2 @ 2.60GHz Model 62 Stepping 4 2600 MHz 8coreRam : DDR-3 64.00 GB Presence Detected Dual Rank 1866 MHzEthernet: NIC Slot 6 Intel(R) Ethernet Converged Network Adapter X540-T2 (WAN,DMZ)Integrated NIC 1 Intel(R) GbE 4P I350-t rNDC (LAN,MANAGEMENT)When Suricata is enabled with IDS/IPS protection the max WAN speed is capped at around 650-670Mbps, with IPS mode disabled I can achieve full 827Mb/s down.I can't say that the ethernet cards we use are not compatible with suricata IPS running on freebsd, because you have witnessed that it works properly in the previous kernel.At the same time, when I follow the dpinger service, the situation is as follows:2021-11-12T02:35:16 dpinger[78904] send_interval 1000ms loss_interval 2000ms time_period 60000ms report_interval 0ms data_len 0 alert_interval 1000ms latency_alarm 500ms loss_alarm 20% dest_addr 2021-11-11T13:01:05 dpinger[62032] WAN_GWv4_ X: sendto error: 55 2021-11-11T02:35:29 dpinger[72741] GATEWAY ALARM: WAN_GWv4_ (Addr: XAlarm: 0 RTT: 13002us RTTd: 125us Loss: 0%) 2021-11-11T02:35:29 dpinger[62032] WAN_GWv4_ X.255.0.37: Clear latency 13002us stddev 125us loss 0% 2021-11-11T02:35:17 dpinger[38016] GATEWAY ALARM: WAN_GWv4_ (Addr: X.255.0.37 Alarm: 1 RTT: 12983us RTTd: 102us Loss: 25%) 2021-11-11T02:35:17 dpinger[62032] WAN_GWv4_ X.255.0.37: Alarm latency 12983us stddev 102us loss 25% 2021-11-11T02:35:14 dpinger[62032] send_interval 1000ms loss_interval 2000ms time_period 60000ms report_interval 0ms data_len 0 alert_interval 1000ms latency_alarm 500ms loss_alarm 20% dest_addr X.255.0.37 bind_addr X.255.0.38 identifier "WAN_GWv4_ " 2021-11-10T17:00:24 dpinger[89102] WAN_GWv4_ X.255.0.37: sendto error: 55It would be great if we could find a solution and suggestion for this problem, thank you for your valuable information sharing.