@SunCatalyst:
the other issue nobody has touched on is the NOISE factor with the 1u and 2u boxes…
1U are USUALLY pretty damn noisy (due to the fans) and if your using this in a home
environment you may not be happy with the Noise.
ALSO.
if the OP is wanting to do Wire speed and Snort / Etc with 10GE , your gonna WANT multiple
cores. NOT a single core. and then theres ECC ram.
The noise depends on the amount of fans, and the fan itself, but yes it makes to much noise for a regular home, But it is ment for co-location in a datacenter, Do not see any reason why to use a 10gbit lan at home :P
about the, single core, I don't think anyone said a single core is better, they did say that snort uses by default a single core and it would be better to get a cpu with a high rating per core. But indeed, a quad core is required for that speeds.
@Downloadski:
@ilaurens:
@Downloadski:
you need to compile the driver for that intel 10 GE card i think.
I have them in my zfsguru nas servers and in 1 it works the other not. That runs freebsd 9.1 and does not have the newest intel drivers included even.
Further it is hard to fill up that 10 GE connection also, i only can put 350 Mbyte/sec through it (source system is not faster)
Because you will have tweak parts yourself, take a look here this is one of the many things you can do to speed it up http://forum.pfsense.org/index.php?topic=42952.0;prev_next=prev
also search on google: network tuning
Thanks, i have no more problems now with the 10GE cards.
I check the logs and it was caused by to low buffers for 10GE cards.
No problem, glad it helped came across it when I was searching for info. Perhaps you can post your speeds here?
@stephenw10:
Yep. I would think that to do 10G Snort you are going to want all the processing power you can possibly muster! ;) That's way out of my experience though.
I was just pointing out that, due to pf's single thread, you need to look at a CPUs single thread rating rather than it's overall benchmarks. I.e. a 2 core, 4GHz CPU is likely to give faster throughput than a 48 core, 1GHz CPU even though such a CPU would have massive processing power on paper. That's ignoring the Snort requirement.
Steve
Yes, you are right, but well it depends how it's used. It's said a single core, is that per instance or per process, there is also something called PFRING which enables you to use multi threading for snort, but i'm not sure how to do that yet nor I have the space to setup a server at the moment :(