That's a superb question... When I check the settings with sysctl -A | grep dev.igb, everything is fine; which means is set to 0. Obviously, it isn't; else, I would not expect to see any change regarding the throughput when typing the settings on console...And, how can I be sure that the other settings related to the NICs are applied correctly ? They all show up fine; but who knows ...Btw, I disabled IPS; just checking is active. I run a smal and well controlled network. I just want to know, in case of some possible problems. With IPS enabled, I achieved close to 300M... 8 cores don't help, afaik... It looks like only one core is used.
what IDS profile are you using?? There is a setting to change how IDS uses the process/cores.
Quote from: Supermule on June 15, 2020, 11:25:18 amwhat IDS profile are you using?? There is a setting to change how IDS uses the process/cores.Sorry, where is it ?
I changed to development firmware upgrade. It's 20.7 now, but still with 11.2 BSD. Performance is significantly improved. I can run now IDS and IPS, with increased rule set (~3000) at 1GB/s; with Hyperscan and net.bpf.zerocopy_enabled=1. The load goes to slightly more than 1 without IPS, and close to 2 with IPS enabled. Powerd is set to hiactive.