OPNsense
  • Home
  • Help
  • Search
  • Login
  • Register

  • OPNsense Forum »
  • English Forums »
  • Zenarmor (Sensei) »
  • exclude IP from sensei
« previous next »
  • Print
Pages: [1]

Author Topic: exclude IP from sensei  (Read 5429 times)

actionhenkt

  • Jr. Member
  • **
  • Posts: 50
  • Karma: 2
    • View Profile
exclude IP from sensei
« on: July 31, 2021, 05:03:51 pm »
Hi,

Sensei is using 100% cpu and is capping my throughput, is it possible to exclude an IP in sensei so sensei does not scan the traffic at all ?
Have added the IP to the exempted network/ip list but sensei is still scanning.
Logged

mb

  • Hero Member
  • *****
  • Posts: 941
  • Karma: 99
    • View Profile
    • Sunny Valley Networks
Re: exclude IP from sensei
« Reply #1 on: July 31, 2021, 05:43:39 pm »
hi @actionhenkt, exempted networks/ip is the way to go.

Is this new (e.g. started after upgrade to 21.7) or has this been an ongoing situation?
Logged

actionhenkt

  • Jr. Member
  • **
  • Posts: 50
  • Karma: 2
    • View Profile
Re: exclude IP from sensei
« Reply #2 on: July 31, 2021, 07:50:13 pm »
Thanks, I already added the IP's but im not sure if this also works to/from external destinations/sources ? When downloading/uploading, with sensei on the max download/upload is around 330/340 mbps, without sensei I get 940mbps.

The issue is not new also had this pre 21.7 just trying to work around it without disabling sensei
Logged

mb

  • Hero Member
  • *****
  • Posts: 941
  • Karma: 99
    • View Profile
    • Sunny Valley Networks
Re: exclude IP from sensei
« Reply #3 on: July 31, 2021, 11:01:29 pm »
What happens if you put sensei onto bypass mode? In the bypass mode, sensei will be just forwarding packets back and forth.
Logged

actionhenkt

  • Jr. Member
  • **
  • Posts: 50
  • Karma: 2
    • View Profile
Re: exclude IP from sensei
« Reply #4 on: August 01, 2021, 11:43:16 am »
setting bypass mode did not make a difference
Logged

mb

  • Hero Member
  • *****
  • Posts: 941
  • Karma: 99
    • View Profile
    • Sunny Valley Networks
Re: exclude IP from sensei
« Reply #5 on: August 01, 2021, 06:05:35 pm »
Got it. Looks like netmap. Can you send a bug-report? Let's have a look at your ethernet drivers & configuration.
Logged

almodovaris

  • Sr. Member
  • ****
  • Posts: 318
  • Karma: 15
    • View Profile
Re: exclude IP from sensei
« Reply #6 on: August 06, 2021, 09:33:30 am »
I have an APU2 and Sensei is in bridge mode. I have whitelisted:

news.eweka.nl
sslreader.eweka.nl
81.171.92.0/24

But Sensei keeps scanning the connection, using one core of the processor above 90%.
Logged
OPNsense HW:

Minisforum Venus series UN100C, 16 GB RAM, 512 GB SSD
T-bao N9N Pro, 16 GB RAM, 512 GB SSD

almodovaris

  • Sr. Member
  • ****
  • Posts: 318
  • Karma: 15
    • View Profile
Re: exclude IP from sensei
« Reply #7 on: August 06, 2021, 10:11:12 am »
When I download the whitelist, it is empty (0 bytes).
Logged
OPNsense HW:

Minisforum Venus series UN100C, 16 GB RAM, 512 GB SSD
T-bao N9N Pro, 16 GB RAM, 512 GB SSD

almodovaris

  • Sr. Member
  • ****
  • Posts: 318
  • Karma: 15
    • View Profile
Re: exclude IP from sensei
« Reply #8 on: August 19, 2021, 03:19:59 pm »
There is a difference between allow connection, but inspect it and do not inspect at all the connection. I am afraid whitelist does the former rather than the later.
Logged
OPNsense HW:

Minisforum Venus series UN100C, 16 GB RAM, 512 GB SSD
T-bao N9N Pro, 16 GB RAM, 512 GB SSD

  • Print
Pages: [1]
« previous next »
  • OPNsense Forum »
  • English Forums »
  • Zenarmor (Sensei) »
  • exclude IP from sensei
 

OPNsense is an OSS project © Deciso B.V. 2015 - 2024 All rights reserved
  • SMF 2.0.19 | SMF © 2021, Simple Machines
    Privacy Policy
    | XHTML | RSS | WAP2