Subcategories

  • Discussions about TNSR

    16 Topics
    54 Posts
    M
    We're happy to announce the release of TNSR software version 25.02. This regularly scheduled release includes additional hardware support, updates, and bug fixes. Here's what's new: Unicast Reverse Path Forwarding: Introducing Unicast Reverse Path Forwarding (uRPF) to prevent IP spoofing attacks. Both "loose" and "strict" modes available. Enhanced BGP Protection: New BGP Roles implementation (RFC 9234) to prevent route leaks and hijacks. Powerful Threat Detection: Multi-threaded Snort 3 integration for advanced IDS/IPS. NETCONF: The NETCONF service has been made available starting with this release. Regular Updates and Maintenance: Updated VPP and DPDK versions and made over 30 bug fixes and stability enhancements. Learn More: Release Notes Blog Video
  • Discussions about TNSR

    60 Topics
    133 Posts
    JonathanLeeJ
    @johnpoz I know I thought maybe he could be my study buddy for a while but never responded so I gave up .
  • Discussions about installing or upgrading TNSR software

    52 Topics
    190 Posts
    S
    Hello everyone .... I am new to security I am facing a problem in Configuring Network (WAN - LAN) in my new virtual machine of PFSense I have installed the OS in an ESXI-8 but i don't know if I am correct or no doing the interfaces Configuring for both (WAN - LAN), Also i don't know how to make traffic pass through the firewall to start monitoring & applying rules Do anyone work or use the same scenario can help me solving problems
  • This topic is deleted!

    1
    0 Votes
    1 Posts
    26 Views
    No one has replied
  • Issue with more than one SR-IOV interface

    7
    0 Votes
    7 Posts
    3k Views
    S
    @derelict Thought i would give this another shot on the latest code v21.01-588~tnsr_v21.07_1~g31b3e823e, but to no avail, but i did find somting interesting using the show hardware-interface command in vppctl it is seeing the non working interface VirtualFunctionEthernet6/0/0 MTU at 9206 and the admin up flag is not present and this error [rte_eth_dev_start[port:1, errno:-22]: Unknown error -22]. any Ideas how to look/debug further into this or do yo know what this error is? I have also included working interface VirtualFunctionEthernet5/0/0 for comparison vpp# sh hardware-interfaces Name Idx Link Hardware VirtualFunctionEthernet5/0/0 1 up VirtualFunctionEthernet5/0/0 Link speed: 10 Gbps RX Queues: queue thread mode 0 main (0) polling Ethernet address 02:09:c0:99:4a:be Intel 82599 VF carrier up full duplex mtu 1500 flags: admin-up pmd maybe-multiseg subif tx-offload intel-phdr-cksum rx-ip4-cksum rx: queues 1 (max 2), desc 1024 (min 32 max 4096 align 8) tx: queues 1 (max 2), desc 1024 (min 32 max 4096 align 8) pci: device 8086:10ed subsystem 8086:000c address 0000:05:00.00 numa 0 max rx packet len: 9728 promiscuous: unicast off all-multicast on vlan offload: strip off filter off qinq off rx offload avail: vlan-strip ipv4-cksum udp-cksum tcp-cksum vlan-filter jumbo-frame scatter keep-crc rss-hash rx offload active: ipv4-cksum jumbo-frame scatter tx offload avail: vlan-insert ipv4-cksum udp-cksum tcp-cksum sctp-cksum tcp-tso multi-segs tx offload active: udp-cksum tcp-cksum multi-segs rss avail: ipv4-tcp ipv4-udp ipv4 ipv6-tcp-ex ipv6-udp-ex ipv6-tcp ipv6-udp ipv6-ex ipv6 rss active: ipv4-tcp ipv6-tcp-ex ipv6-tcp ipv6-udp ipv6-ex tx burst function: ixgbe_xmit_pkts rx burst function: ixgbe_recv_scattered_pkts_vec tx frames ok 86 tx bytes ok 7258 rx frames ok 1325 rx bytes ok 191694 extended stats: rx_good_packets 1325 tx_good_packets 86 rx_good_bytes 191694 tx_good_bytes 7258 rx_multicast_packets 1550 VirtualFunctionEthernet6/0/0 2 up VirtualFunctionEthernet6/0/0 Link speed: 10 Gbps RX Queues: queue thread mode 0 main (0) polling Ethernet address 02:09:c0:c1:84:fc Intel 82599 VF carrier up full duplex mtu 9206 flags: pmd maybe-multiseg subif tx-offload intel-phdr-cksum rx-ip4-cksum rx: queues 1 (max 2), desc 1024 (min 32 max 4096 align 8) tx: queues 1 (max 2), desc 1024 (min 32 max 4096 align 8) pci: device 8086:10ed subsystem 8086:000c address 0000:06:00.00 numa 0 max rx packet len: 9728 promiscuous: unicast off all-multicast off vlan offload: strip off filter on qinq off rx offload avail: vlan-strip ipv4-cksum udp-cksum tcp-cksum vlan-filter jumbo-frame scatter keep-crc rss-hash rx offload active: ipv4-cksum jumbo-frame scatter tx offload avail: vlan-insert ipv4-cksum udp-cksum tcp-cksum sctp-cksum tcp-tso multi-segs tx offload active: udp-cksum tcp-cksum multi-segs rss avail: ipv4-tcp ipv4-udp ipv4 ipv6-tcp-ex ipv6-udp-ex ipv6-tcp ipv6-udp ipv6-ex ipv6 rss active: ipv4-tcp ipv6-tcp-ex ipv6-tcp ipv6-udp ipv6-ex tx burst function: ixgbe_xmit_pkts rx burst function: ixgbe_recv_pkts rx frames ok 4294966922 rx bytes ok 68719442425 Errors: rte_eth_dev_start[port:1, errno:-22: Unknown error -22 Thanks.
  • This topic is deleted!

    1
    0 Votes
    1 Posts
    12 Views
    No one has replied
  • Is vpp_main CPU 100% normal?

    3
    0 Votes
    3 Posts
    2k Views
    J
    @gabacho4 Thanks!
  • CLI syntax error: "int WAN": Unknown command

    5
    0 Votes
    5 Posts
    2k Views
    J
    @jbelthoff said in CLI syntax error: "int WAN": Unknown command: Active Interface ens19 Okay nevermind, I see I have to remove the "Active" interfaces...
  • netgate-route API (21.07) adding a static route

    1
    0 Votes
    1 Posts
    839 Views
    No one has replied
  • Is TNSR ready for prime time?

    4
    0 Votes
    4 Posts
    2k Views
    johnpozJ
    @insanesplash I get yeah, my reply is pure guess work on my part as well ;) Since I have no insight to who or how many etc. are actually using TNSR in large scale environments or even small ones.. It could be 1000's it could be 1.. I was more just commenting/guessing to why you don't see many posts about it here on the forums. I have not done any personal testing/playing with it as of yet myself - because well I don't have the lab to do it justice for one ;)
  • Will the TNSR education series on youtube be completed?

    5
    1 Votes
    5 Posts
    2k Views
    I
    Seems the video link on the twitter post no longer works.
  • Sub Interface not removed

    1
    0 Votes
    1 Posts
    650 Views
    No one has replied
  • Home+lab feedback

    1
    2 Votes
    1 Posts
    871 Views
    No one has replied
  • This topic is deleted!

    1
    0 Votes
    1 Posts
    30 Views
    No one has replied
  • TNSR for me

    1
    0 Votes
    1 Posts
    850 Views
    No one has replied
  • Does TNSR have Inter-VDOM links similar to Fortinet

    2
    0 Votes
    2 Posts
    1k Views
    DerelictD
    @williwinkie You can route between VRFs in some cases. Can you explain what you are looking to accomplish in more detail? I have not spent significant time with sonicwalls.
  • This topic is deleted!

    1
    0 Votes
    1 Posts
    19 Views
    No one has replied
  • VRRP responds only on first arp

    Moved
    1
    0 Votes
    1 Posts
    960 Views
    No one has replied
  • 0 Votes
    6 Posts
    2k Views
    DerelictD
    @gabacho4 Yes, there is an open feature request for the same. No timeline that I can see.
  • Failover or load-balancing of two dhcp WAN links ?

    4
    0 Votes
    4 Posts
    1k Views
    DerelictD
    @ulrik said in Failover or load-balancing of two dhcp WAN links ?: o you know if it is possible to set the priority of the default route assigned by the dhcp client? Not at this time, no. I have submitted a feature request for this capability.
  • Syntax error deleting interface from dataplane

    Moved
    3
    0 Votes
    3 Posts
    1k Views
    U
    @derelict Too late :-) i decided to reinstall and create the host interface during install.
  • Try as Home/SOHO Router/Firewall

    3
    3 Votes
    3 Posts
    2k Views
    A
    @mr-rosh To get this package, i have to get license and there is no license in the HOME+LAB version. If i could, i'll do :) They may include avahi in defaults packages. The package you listed is for pfsense not TNSR. Thank you for your post anyways.
  • Proxmox KVM 'issues' with TNSR?

    3
    0 Votes
    3 Posts
    1k Views
    P
    Hello! I had the same issue when tried to increase cpu workers count, but I found solution. If you would like to have more cpu workers, you have to increase heap-size param. https://docs.netgate.com/tnsr/en/latest/advanced/dataplane-monitoring.html#dataplane-statseg I set heap-size 500M and 7 cpu workers.
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.