OPNsense
  • Home
  • Help
  • Search
  • Login
  • Register

  • OPNsense Forum »
  • English Forums »
  • Intrusion Detection and Prevention »
  • IDS/IPS performance hit - does this look normal...
« previous next »
  • Print
Pages: [1]

Author Topic: IDS/IPS performance hit - does this look normal...  (Read 2089 times)

jeffmcfarlin

  • Newbie
  • *
  • Posts: 5
  • Karma: 0
    • View Profile
IDS/IPS performance hit - does this look normal...
« on: January 06, 2023, 07:49:09 pm »
New to OpnSense, but really liking it so far.

Have IDS/IPS up using abuse.ch* and ET.telemetry* on the LAN interface on - Intel(R) Core(TM) i5-6400 CPU @ 2.70GHz (4 cores, 4 threads), w/8G memory, 2 Broadcom BCM57xx single port cards with a typical NAT setup (FiOS single static IP WAN, and ~75 or so devices behind the firewall on a single /24 LAN).

I'm seeing about a 20% performance hit in terms of raw throughput when in IPS mode on outbound traffic thru the FW to the internet with the above setup. Seem about right? (216,358 rules in total, all in alert mode for the moment.)

Jeff
« Last Edit: January 06, 2023, 07:53:17 pm by jeffmcfarlin »
Logged

FullyBorked

  • Sr. Member
  • ****
  • Posts: 353
  • Karma: 24
    • View Profile
Re: IDS/IPS performance hit - does that look normal...
« Reply #1 on: January 06, 2023, 07:56:06 pm »
Quote from: jeffmcfarlin on January 06, 2023, 07:49:09 pm
New to OpnSense, but really liking it so far. Using abuse.ch* and ET.telemetry* on the LAN interface on - Intel(R) Core(TM) i5-6400 CPU @ 2.70GHz (4 cores, 4 threads), w/8G memory, 2 Broadcom BCM57xx single port cards with a typical NAT setup (FiOS single static IP, and ~75 or so devices behind the firewall on a single /24).

I'm seeing about a 20% performance hit when in IPS mode on outbound traffic thru the FW to the internet with the above setup. Seem about right? (216,358 rules)

Jeff

I wouldn't expect a huge hit, your CPU is decent.  Have you disabled hardware offloading Interfaces > Settings?  I have an i3-9100 8GB of ram as well, and 1200Mbps Xfinity and the performance hit in imperceivable to me.  However I haven't used Suricata on my internal interfaces in some time now.  I only use it on my DMZ interface that hosts a few sites/game servers and Zenarmor on my other interfaces. 
Logged

jeffmcfarlin

  • Newbie
  • *
  • Posts: 5
  • Karma: 0
    • View Profile
Re: IDS/IPS performance hit - does this look normal...
« Reply #2 on: January 06, 2023, 08:07:55 pm »
Yes, hardware offloading is disabled. I've got 1g/1g for internet. I've read about ppl using Zenarmor in conjunction with Suricata. Like ZA on the LAN and Suricata on the WAN. Hmm. Lots to think about.

Jeff
Logged

  • Print
Pages: [1]
« previous next »
  • OPNsense Forum »
  • English Forums »
  • Intrusion Detection and Prevention »
  • IDS/IPS performance hit - does this look normal...
 

OPNsense is an OSS project © Deciso B.V. 2015 - 2024 All rights reserved
  • SMF 2.0.19 | SMF © 2021, Simple Machines
    Privacy Policy
    | XHTML | RSS | WAP2