Its not that hard...We run that everyday and has for 3+ yrs. It just takes serious hardware.
For example, for an "High-Performance-Setup" we using OPNSense in an virtualized HA-Stack (Proxmox).Search for CPU´s with high clock rate.Some "standard"-Blades with modern Xeon´s or AMD Epyc should be enough for Suricata Example above, 2 OPNSense in HA with Suricata (with a lot! of rules), average 20 TB mixed traffic per day, the CPU idles around 2-4%.
Same thing here (guenti_r):QuoteFor example, for an "High-Performance-Setup" we using OPNSense in an virtualized HA-Stack (Proxmox).Search for CPU´s with high clock rate.Some "standard"-Blades with modern Xeon´s or AMD Epyc should be enough for Suricata Example above, 2 OPNSense in HA with Suricata (with a lot! of rules), average 20 TB mixed traffic per day, the CPU idles around 2-4%.Screenshot or it didnt happen. Show some benchmark results with Suricata in IPS mode with 10Gbps throughput instead of talking around it.
Really annoying that I cant post snips here.... with CTRL+V.Makes it alot easier.16CORE XEON 3.00 gHz running "the other sense".Quote from: seed on December 18, 2022, 09:27:10 pmSame thing here (guenti_r):QuoteFor example, for an "High-Performance-Setup" we using OPNSense in an virtualized HA-Stack (Proxmox).Search for CPU´s with high clock rate.Some "standard"-Blades with modern Xeon´s or AMD Epyc should be enough for Suricata Example above, 2 OPNSense in HA with Suricata (with a lot! of rules), average 20 TB mixed traffic per day, the CPU idles around 2-4%.Screenshot or it didnt happen. Show some benchmark results with Suricata in IPS mode with 10Gbps throughput instead of talking around it.
Hm, in my Tests I had a more powerful machine. Sure its IPS or not IDS?
Screenshot or it didnt happen. Show some benchmark results with Suricata in IPS mode with 10Gbps throughput instead of talking around it.