kern.ipc.nmbclusters=1000000kern.ipc.nmbjumbop=524288hw.intr_storm_threshold=10000net.inet.tcp.tso=0net.isr.maxthreads=-1net.isr.bindthreads=1dev.ixl.0.iflib.override_qs_enable=1dev.ixl.1.iflib.override_qs_enable=1dev.ixl.0.iflib.override_nrxqs=128dev.ixl.1.iflib.override_nrxqs=128dev.ixl.0.iflib.override_ntxqs=128dev.ixl.1.iflib.override_ntxqs=128dev.ixl.0.iflib.override_nrxds=128dev.ixl.1.iflib.override_nrxds=128dev.ixl.0.iflib.override_ntxds=128dev.ixl.1.iflib.override_ntxds=128
After all my woes (https://forum.opnsense.org/index.php?topic=25263.15) I managed to get forwarding performance up to ~5 Gb/s through the Chelsio T520-SO-CR and Ryzen hardware so bit weird that your performance is is so low after having followed similar steps. Will be interesting to hear your results on Intel X710. And as mentioned on Linux also. NB that's a side project for me as well - setting up a minimal Debian 11 with routing and firewall through nftables, also unbound and dhcp server etc. Not got as far as live-testing it yet but curious how it will perform in comparison.
Good to hear those speeds are achievable. What NICs do you guys use? Did you have to fiddle with tunables in order to get the performance?Fwiw I looked at Vyatta also but didn’t really see the point. Nftables in itself is straightforward enough so not so much gained vs a vanilla Debian - where you also get more flexibility. In both cases losing out vs OpnSense’s awesome gui.
you seem not understand the BSD ecosystem. It's not your fault and that's OK.
Mellanox ConnectX-3 10gb SFP dual port here, 1 to WAN and 1 to my LAN. No tunables set up.
Quote from: jclendineng on June 07, 2022, 12:15:27 amMellanox ConnectX-3 10gb SFP dual port here, 1 to WAN and 1 to my LAN. No tunables set up.That’s interesting. I have Chelsio NICs, which are supposedly well supported, but I had to mess around with tunables and settings before I managed to get netmap to run in native mode and offer half decent performance. https://forum.opnsense.org/index.php?topic=25263.0
Quote from: lilsense on June 06, 2022, 11:49:44 pmyou seem not understand the BSD ecosystem. It's not your fault and that's OK.Thank you for your thoughtful contribution to the topic.