Some of the tunables and settings do come with a resource price. Try reducing the interrupt rate. The queue size is a NIC dependent setting and depends of the buffer size in the NIC itself.
With IPS/IDS my internet speed drops to 60mbs from 300mbs. I want to try your suggestions. Appreciate if you could let me know how to check ports used by IPS"Set to 0 (<x>) for every port used by IPSdev.igb.<x>.fc: value=0"I followed "Fast and easy way to protect your home and/or small office network with OPNsense" for my Initial setupThanks
Quote from: dcol on April 10, 2018, 01:02:26 amSome of the tunables and settings do come with a resource price. Try reducing the interrupt rate. The queue size is a NIC dependent setting and depends of the buffer size in the NIC itself.Thanks, will try with interrupt value of 42000 and see if it gets a bit better
Quote from: Evil_Sense on April 10, 2018, 01:15:13 amQuote from: dcol on April 10, 2018, 01:02:26 amSome of the tunables and settings do come with a resource price. Try reducing the interrupt rate. The queue size is a NIC dependent setting and depends of the buffer size in the NIC itself.Thanks, will try with interrupt value of 42000 and see if it gets a bit better Hi EVIL_Sense,after changing the 42000 value, have you noticed some changes / speed ?i am willing to get this configured on a production soon as we are from 1024MB when IDS is activated we reach 400MB
Quote from: Julien on April 21, 2018, 11:00:17 pmQuote from: Evil_Sense on April 10, 2018, 01:15:13 amQuote from: dcol on April 10, 2018, 01:02:26 amSome of the tunables and settings do come with a resource price. Try reducing the interrupt rate. The queue size is a NIC dependent setting and depends of the buffer size in the NIC itself.Thanks, will try with interrupt value of 42000 and see if it gets a bit better Hi EVIL_Sense,after changing the 42000 value, have you noticed some changes / speed ?i am willing to get this configured on a production soon as we are from 1024MB when IDS is activated we reach 400MBWell, with 42000 I got a reasonable balance between resource usage and (at least I hope) good/better networking performance.
Quote from: Evil_Sense on April 21, 2018, 11:29:38 pmQuote from: Julien on April 21, 2018, 11:00:17 pmQuote from: Evil_Sense on April 10, 2018, 01:15:13 amQuote from: dcol on April 10, 2018, 01:02:26 amSome of the tunables and settings do come with a resource price. Try reducing the interrupt rate. The queue size is a NIC dependent setting and depends of the buffer size in the NIC itself.Thanks, will try with interrupt value of 42000 and see if it gets a bit better Hi EVIL_Sense,after changing the 42000 value, have you noticed some changes / speed ?i am willing to get this configured on a production soon as we are from 1024MB when IDS is activated we reach 400MBWell, with 42000 I got a reasonable balance between resource usage and (at least I hope) good/better networking performance.Can you share the value ? how much is before and after the IDS is activated ?i am willing to configure this as the firewall is not near to me, if things missed up i will need to travel like 4 hrs go and 4 hr back.
Quote from: Julien on April 22, 2018, 10:32:13 pmQuote from: Evil_Sense on April 21, 2018, 11:29:38 pmQuote from: Julien on April 21, 2018, 11:00:17 pmQuote from: Evil_Sense on April 10, 2018, 01:15:13 amQuote from: dcol on April 10, 2018, 01:02:26 amSome of the tunables and settings do come with a resource price. Try reducing the interrupt rate. The queue size is a NIC dependent setting and depends of the buffer size in the NIC itself.Thanks, will try with interrupt value of 42000 and see if it gets a bit better Hi EVIL_Sense,after changing the 42000 value, have you noticed some changes / speed ?i am willing to get this configured on a production soon as we are from 1024MB when IDS is activated we reach 400MBWell, with 42000 I got a reasonable balance between resource usage and (at least I hope) good/better networking performance.Can you share the value ? how much is before and after the IDS is activated ?i am willing to configure this as the firewall is not near to me, if things missed up i will need to travel like 4 hrs go and 4 hr back.I don't use IDS, so I can't give a statement on it.Since I didn't write down the original settings and didn't make speed tests before and after, I'm not really able to provide reliable values. I could however try to remove the settings and measuring against the current state tomorrow.