Home
Help
Search
Login
Register
OPNsense Forum
»
English Forums
»
Intrusion Detection and Prevention
»
Maltrail vs. Suricata
« previous
next »
Print
Pages: [
1
]
Author
Topic: Maltrail vs. Suricata (Read 2099 times)
labsy
Jr. Member
Posts: 59
Karma: 1
Maltrail vs. Suricata
«
on:
September 28, 2023, 10:08:26 pm »
Hi,
in previous versions I've been always using
Suricata
, but with 23.x it begun consuming a lot of CPU. Maybe it was due to some inheritable settings, maybe rules vs policies...dunno.
So I got rid of Suricata for now and gave a try to
Maltrail
. I did not get into details, Suricata seems more powerfull, but performance-wise I notice all web services behind my OPNSense are now (with Maltrail instead of Suricata) noticeably
more responsive and faster
. Also CPU load is cut on half now.
Thoughts?
Logged
mimugmail
Hero Member
Posts: 6766
Karma: 494
Re: Maltrail vs. Suricata
«
Reply #1 on:
September 29, 2023, 06:00:00 am »
Both are not really compareable. How many rules/lists do you use in Suri?
Logged
WWW:
www.routerperformance.net
Support plans:
https://www.max-it.de/en/it-services/opnsense/
Commercial Plugins (German):
https://opnsense.max-it.de/
labsy
Jr. Member
Posts: 59
Karma: 1
Re: Maltrail vs. Suricata
«
Reply #2 on:
September 29, 2023, 07:21:34 pm »
Huh...tough question, because I shut it down and removed all rules and policies (...to be ready for new installation, once v. 7 comes out). But as I remember, I scrolled down quite a lot, so it was definitelly more than 50 or even close to 100 rules.
I think there's also a question, what I need:
This is a small webhosting setup, I only want to protect a dozen of WEB and MAIL servers behind OPNSense against attacks from internet. There are no client computers behind, so no web surfing, mail clients etc to protect.
On the other hand, I do not want to slow down package transition too much, so to keep services responsive.
«
Last Edit: September 29, 2023, 07:24:20 pm by labsy
»
Logged
Print
Pages: [
1
]
« previous
next »
OPNsense Forum
»
English Forums
»
Intrusion Detection and Prevention
»
Maltrail vs. Suricata