Would those tips be general , and also usable (recommended) for a Qotom i5 setup w. 8G Ram ?
It is never really able to reproduce on any hardware with the same effect or on custom hardware with the same
effect. As an small example;
Broadcom 10 GbE NICs (not all, but many) use more narrow down the entire mbuf size (65.000) and get often success
Intel NICs are often gets served when you high them up between 125000 till 1000000!
So freeing some things up might be a good sounding idea, but not for nay user or any case of usage fo sure!
Please accept it is more or less something or more things I´ve seen peoples are starting a service,
running a packet or in general setting up some things and even after this many or some are running
in a trap or getting problems after the installation.
It is able to get the same result or success but not even and with a guaranty for that, it all depends on the
entire hardware and also the pfSense Version itself because not each version likes the other one pending on
bug fixes newer functions, options and protocols or given services, it more like a hunting game you will win.
and also usable (recommended) for a Qotom i5 setup w. 8G Ram
Let us both imagine you are using firewall, vpn, snort, squid, SquidGuard and pfBlockerNG
and you turns on the pfBlockerNG & DNSBL + TDL with many IP lists so your ram is going
down very fast nearly complete in usage, so it makes no sense to say let us highing up the
mbuf size, but if you gets in problems or you see issues and narrow down the entire IP lists
in pfBlockerNG that will be in usage, you could do this to solve around any other problems.
BIOS settings: (if needed)
activate the Hyper threading (HT)
set the IPMI port to dedicated (often or sometimes shared with the WAN port as fall back)
Often peoples are reporting they was imagine more from the higher tech spec hardware and because
the HT function was disabled in the BIOS, so why not telling others please don´t forget to turn it on?
Did your Qotom box have such a setting the BIOS, if so then try it out and give us (forum members)
a feedback on this please!!!
The IPMI Port on some mainboards mostly Supermicro, and we are talking here about a Supermicro
Xeon D-15xx vs an Intel Xeon E3 system, are the fall back port associated to the WAN port! So if
then the WAN is one time failing the WAN falls back to the IPMI and you are trying to get the access
to the Internet back and again and again but without success or any clue why you can´t do so or
plain why you would not be able to do so!
NIC tunings: (if needed)
choose ZFS file system and TRIM support will be enabled automatically
high up mbuf size to something between 125000 - 1000000
narrow down the amount of num.queues to 1 till 4
enable PowerD (high adaptive)
If you need TRIM or you wish it to enable nice to know that since version 2.4.0 ZFS is
automatic enabling this for you
Pending on the used NIC driver and CPU for each NIC port pfSense will be open or create
queues and they can be filled more (mbuf size 1000000) or less (mbuf size 65000) and on
top of this the amount of this queues will be also able to set up like 1 queue till 4 or more
queues likes needed or well matching.
PowerD will be bringing the CPU to scale up if needed and also vice versa scaling down of
your pfSense box is not so hard stressed by traffic or functions.
OpenVPN settings: (if needed)
enables Intel RDRAND (if supported by the hardware)
activate UDP fast I/O support
enable LZO compression if able to do so on both sites
set the buffer to 2 MB less or higher could also be matching
AES-NI is activated by default since the pfSense version 2.4.0
And this is quitly the greatest part where you weill be able to play around with for weeks to
get the best settings matching to your configuration and bringing you the most benefits.
Please don´t forget please you can win and be happy with only one setting and/or with all or
some of them together. I personally mean that mostly, many things are playing more well
together as only one hint.
VPN is a both ended "thing" and if both ends are enabling LZO compression or fast I/O support
it would makes more sin to me, Intel RDRAND must be supported by hardware and the buffer is
more or less pending on your RAM size. And what benefit you will see at your pfSense box or
based on the hardware you are using.