OPNsense
  • Home
  • Help
  • Search
  • Login
  • Register

  • OPNsense Forum »
  • English Forums »
  • Intrusion Detection and Prevention »
  • IDS enabled HighPing / Timeout
« previous next »
  • Print
Pages: [1]

Author Topic: IDS enabled HighPing / Timeout  (Read 1702 times)

msmarcapo

  • Newbie
  • *
  • Posts: 12
  • Karma: 0
    • View Profile
IDS enabled HighPing / Timeout
« on: January 10, 2023, 11:14:10 am »
Hey,
we are using OPNsense 22.7.10_2-amd64 on an AMD EPYC 7272 12-Core Processor (12 cores, 24 threads).
We enabled IDS with disabled Promiscuous Mode and Logging. As pattern matcher we setup hyperscan. Hardware offload is disabled.
IDS is restricted to the internet / uplink Interface and specific networks. The Speed is gigabit.
We've downloaded and enabled all rules.

We can reproduce that after enabling IDS and waiting for 5-15mins we got highpings and timeouts every few pings between hosts.
Its unusable for us at this state. This Hardware should be play with IDS easily we think?

How can we prevent this? What are we missing?

Thanks for Ideas!
Logged

msmarcapo

  • Newbie
  • *
  • Posts: 12
  • Karma: 0
    • View Profile
Re: IDS enabled HighPing / Timeout
« Reply #1 on: January 31, 2023, 04:37:17 pm »
Solved the issue.
The DNS-Server in the Opnsense was wrong. So it cant resolve internal DNS-Records correctly.
After solved this IDS works fine without high CPU-Load or highpings.

Logged

mschmidt

  • Newbie
  • *
  • Posts: 15
  • Karma: 0
    • View Profile
Re: IDS enabled HighPing / Timeout
« Reply #2 on: February 01, 2023, 10:49:41 am »
We have the same problem on one of our installations.
can you specify what you did to your dns config?
Logged

msmarcapo

  • Newbie
  • *
  • Posts: 12
  • Karma: 0
    • View Profile
Re: IDS enabled HighPing / Timeout
« Reply #3 on: February 02, 2023, 09:49:00 am »
Quote from: mschmidt on February 01, 2023, 10:49:41 am
We have the same problem on one of our installations.
can you specify what you did to your dns config?

We installed the Server in an complete fresh environment which didnt contains an own DNS-Server at this moment. So we add an public dns server entry on the install dialoge.
We forgot to change that setting, so no internale name cant be resolved from opnsense.
Logged

mschmidt

  • Newbie
  • *
  • Posts: 15
  • Karma: 0
    • View Profile
Re: IDS enabled HighPing / Timeout
« Reply #4 on: February 02, 2023, 05:54:27 pm »
thank you :)
Logged

  • Print
Pages: [1]
« previous next »
  • OPNsense Forum »
  • English Forums »
  • Intrusion Detection and Prevention »
  • IDS enabled HighPing / Timeout
 

OPNsense is an OSS project © Deciso B.V. 2015 - 2024 All rights reserved
  • SMF 2.0.19 | SMF © 2021, Simple Machines
    Privacy Policy
    | XHTML | RSS | WAP2