OPNsense
  • Home
  • Help
  • Search
  • Login
  • Register

  • OPNsense Forum »
  • Archive »
  • 17.7 Legacy Series »
  • [SOLVED] [Suricata] Suricata dropping traffic with IPS.
« previous next »
  • Print
Pages: 1 [2]

Author Topic: [SOLVED] [Suricata] Suricata dropping traffic with IPS.  (Read 19367 times)

Julien

  • Hero Member
  • *****
  • Posts: 666
  • Karma: 33
    • View Profile
Re: [SOLVED] [Suricata] Suricata dropping traffic with IPS.
« Reply #15 on: November 09, 2017, 10:36:41 am »
Quote from: Fabio83 on November 09, 2017, 09:28:06 am
Quote from: xupetas on November 09, 2017, 09:10:38 am

Hello Julien,

Is the difficulty being shown at any speed? Or is only felt when you reach 200mbps?

Thanks!

In my environment I tested it via iperf to a System in another Subnet or over WAN:
Virtio and IPS disabled: ~900Mbit/s
E1000 and IPS disabled: ~200-250Mbit/s
VMXNET3 and IPS disabled: ~500Mbit/s
VMXNET3 and IPS enabled: ~300-400Mbit/s

Grretings,
Fabio
Thank you Fabio,
the connections works only its dropped significly down.
i tried everything but nothing helped.
Logged
OPNsense 23.1.7_3-amd64
FreeBSD 13.1-RELEASE-p7
OpenSSL 1.1.1t 7 Feb 2023

Fabio83

  • Newbie
  • *
  • Posts: 9
  • Karma: 0
    • View Profile
Re: [SOLVED] [Suricata] Suricata dropping traffic with IPS.
« Reply #16 on: November 09, 2017, 11:14:25 am »
Quote from: Julien on November 09, 2017, 10:36:41 am

Thank you Fabio,
the connections works only its dropped significly down.
i tried everything but nothing helped.

Hello Julien.

What for an Virtualization Host and qemu-Version you are using?
Logged

Julien

  • Hero Member
  • *****
  • Posts: 666
  • Karma: 33
    • View Profile
Re: [SOLVED] [Suricata] Suricata dropping traffic with IPS.
« Reply #17 on: November 09, 2017, 01:37:56 pm »
Quote from: Fabio83 on November 09, 2017, 11:14:25 am
Quote from: Julien on November 09, 2017, 10:36:41 am

Thank you Fabio,
the connections works only its dropped significly down.
i tried everything but nothing helped.

Hello Julien.

What for an Virtualization Host and qemu-Version you are using?
Hi Fabio,
I am on a hardware with
i5 CPU / 8GB Memory / 64 SSD GB HDD/ Intel 82574L Gigabit Ethernet
Logged
OPNsense 23.1.7_3-amd64
FreeBSD 13.1-RELEASE-p7
OpenSSL 1.1.1t 7 Feb 2023

Fabio83

  • Newbie
  • *
  • Posts: 9
  • Karma: 0
    • View Profile
Re: [SOLVED] [Suricata] Suricata dropping traffic with IPS.
« Reply #18 on: November 09, 2017, 04:18:00 pm »
Quote from: Julien on November 09, 2017, 01:37:56 pm
Hi Fabio,
I am on a hardware with
i5 CPU / 8GB Memory / 64 SSD GB HDD/ Intel 82574L Gigabit Ethernet

So, if you are running your OPNsense on Hardware directly -> check out your current Pattern matcher (under Services/IntrusionDetection). For better Performance you could try "Hyperscan" instead of "Aho-Corasick".

Fabio
Logged

dragon2611

  • Jr. Member
  • **
  • Posts: 94
  • Karma: 4
    • View Profile
Re: [SOLVED] [Suricata] Suricata dropping traffic with IPS.
« Reply #19 on: November 09, 2017, 04:47:48 pm »
Last time I tried to enable IPS on a VM running in Proxmox (KVM) it would just stop passing traffic and usually need a reboot to get going again, this was with the virtIO drivers.

it was an N3150 so gutless but it wasn't a CPU usage problem it was the VirtIO drivers really don't seem to play nice with IDS.

It's the reason I don't have the IDS turned on in any of my opnsense boxes because with most of them being virtual I can't risk it.
Logged

Julien

  • Hero Member
  • *****
  • Posts: 666
  • Karma: 33
    • View Profile
Re: [SOLVED] [Suricata] Suricata dropping traffic with IPS.
« Reply #20 on: November 09, 2017, 05:48:40 pm »
Quote from: Fabio83 on November 09, 2017, 04:18:00 pm
Quote from: Julien on November 09, 2017, 01:37:56 pm
Hi Fabio,
I am on a hardware with
i5 CPU / 8GB Memory / 64 SSD GB HDD/ Intel 82574L Gigabit Ethernet

So, if you are running your OPNsense on Hardware directly -> check out your current Pattern matcher (under Services/IntrusionDetection). For better Performance you could try "Hyperscan" instead of "Aho-Corasick".

Fabio
I have tried both Hyperscan and aho now is running on Default.
both are providing a poor performance.

with hyperscan I reach 400 Mbps and with Aho-Corasich and Default I reach 340 Mbps
« Last Edit: November 09, 2017, 06:06:24 pm by Julien »
Logged
OPNsense 23.1.7_3-amd64
FreeBSD 13.1-RELEASE-p7
OpenSSL 1.1.1t 7 Feb 2023

Julien

  • Hero Member
  • *****
  • Posts: 666
  • Karma: 33
    • View Profile
Re: [SOLVED] [Suricata] Suricata dropping traffic with IPS.
« Reply #21 on: November 16, 2017, 07:17:37 pm »
Does anybody has a idea about why the speed is 50% down when Suricata on is ?
Logged
OPNsense 23.1.7_3-amd64
FreeBSD 13.1-RELEASE-p7
OpenSSL 1.1.1t 7 Feb 2023

franco

  • Administrator
  • Hero Member
  • *****
  • Posts: 17707
  • Karma: 1618
    • View Profile
Re: [SOLVED] [Suricata] Suricata dropping traffic with IPS.
« Reply #22 on: November 17, 2017, 04:49:25 am »
It depends on your setup. If you use local services like proxies on your OPNsense and all of this traffic hits the proxy, the proxy penalty usage is 50% because you not only end up reading incoming packets, but also rewiriting or recreating packets which caused buffers to be copied for sending, and that hurts your overall performance.

Especially with a HTTP speed test and web proxy enabled you‘re testing your maximum speed as configured, but maybe not as expected. ;)


Cheers,
Franco
Logged

Julien

  • Hero Member
  • *****
  • Posts: 666
  • Karma: 33
    • View Profile
Re: [SOLVED] [Suricata] Suricata dropping traffic with IPS.
« Reply #23 on: November 17, 2017, 06:12:06 pm »
Quote from: franco on November 17, 2017, 04:49:25 am
It depends on your setup. If you use local services like proxies on your OPNsense and all of this traffic hits the proxy, the proxy penalty usage is 50% because you not only end up reading incoming packets, but also rewiriting or recreating packets which caused buffers to be copied for sending, and that hurts your overall performance.

Especially with a HTTP speed test and web proxy enabled you‘re testing your maximum speed as configured, but maybe not as expected. ;)


Cheers,
Franco
Well Explained Franco, I thought too it has something to do with the proxy but we have no proxy configured in this configuration.
the test is going over http  http://beta.speedtest.net/ and it shows 320Mbps/s

is was actually wondering if the speedtest result are our actuall speed or not.

when we test using https   https://fast.com/en/gb/ its shows 520 Mbps/s

Logged
OPNsense 23.1.7_3-amd64
FreeBSD 13.1-RELEASE-p7
OpenSSL 1.1.1t 7 Feb 2023

  • Print
Pages: 1 [2]
« previous next »
  • OPNsense Forum »
  • Archive »
  • 17.7 Legacy Series »
  • [SOLVED] [Suricata] Suricata dropping traffic with IPS.
 

OPNsense is an OSS project © Deciso B.V. 2015 - 2024 All rights reserved
  • SMF 2.0.19 | SMF © 2021, Simple Machines
    Privacy Policy
    | XHTML | RSS | WAP2