Subcategories

  • Discussions about TNSR

    16 Topics
    54 Posts
    M
    We're happy to announce the release of TNSR software version 25.02. This regularly scheduled release includes additional hardware support, updates, and bug fixes. Here's what's new: Unicast Reverse Path Forwarding: Introducing Unicast Reverse Path Forwarding (uRPF) to prevent IP spoofing attacks. Both "loose" and "strict" modes available. Enhanced BGP Protection: New BGP Roles implementation (RFC 9234) to prevent route leaks and hijacks. Powerful Threat Detection: Multi-threaded Snort 3 integration for advanced IDS/IPS. NETCONF: The NETCONF service has been made available starting with this release. Regular Updates and Maintenance: Updated VPP and DPDK versions and made over 30 bug fixes and stability enhancements. Learn More: Release Notes Blog Video
  • Discussions about TNSR

    61 Topics
    134 Posts
    JonathanLeeJ
    @johnpoz I know I thought maybe he could be my study buddy for a while but never responded so I gave up .
  • Discussions about installing or upgrading TNSR software

    52 Topics
    191 Posts
    A
    @Said.Fathy , Hi Said .. I'd strongly recommend Lawrence Systems' youtube channel... it's the best as far as pfsense is concerned.. from beginner to pro https://www.youtube.com/@LAWRENCESYSTEMS
  • This topic is deleted!

    4
    0 Votes
    4 Posts
    24 Views
  • This topic is deleted!

    4
    0 Votes
    4 Posts
    26 Views
  • TNSR Business Confusion.

    3
    0 Votes
    3 Posts
    907 Views
    S
    The pricing from here is $500 per year for the Business Pro plan. There is no minimum/maximum speed, it's flat rate. It's not a replacement product for pfSense so your network doesn't need to be 'big enough' to benefit from it, you may use it even for the smallest networks if you wanted.
  • TNSR on AMD EPYC ROME

    7
    0 Votes
    7 Posts
    2k Views
    kiokomanK
    @prx said in TNSR on AMD EPYC ROME: 16.26.1040 i think it was specific for that firmware revision but for the network card you mentioned : tested platform https://doc.dpdk.org/guides-20.02/rel_notes/release_20_02.html#tested-platforms Mellanox ConnectX-5 Ex EN 100G MCX516A-CDAT (2x100G) Host interface: PCI Express 4.0 x16 Device ID: 15b3:1019 Firmware version: 16.27.1000 and above
  • Speeds through TNSR

    3
    0 Votes
    3 Posts
    618 Views
    kiokomanK
    also, That is the kind of speed I have when one of my side it's not set with Mtu 9000, double-check that on all your machine. I found this tuning useful for Ubuntu https://fasterdata.es.net/host-tuning/linux/
  • Setting up tnsr & Snort

    7
    1
    0 Votes
    7 Posts
    1k Views
    Galactica_ActualG
    Netgate provided an example on how to integrate Snort to create an IDS back in 2018, which needs an update as TNSR has continued to evolve. From a 2018 blog: TNSR-IDS is written in the Go programming language, allowing it to be easily compiled for a large number of OS and architectures. Details, source code, and setup instructions (including TNSR, SNORT and ERSPAN) can be found at the TNSR-IDS Project GitHub Repository(https://github.com/Netgate/TNSR_IDS). A README file is included in the repository that provides a lot of detail about the process, as well as a TNSR-Snort setup file that gives detailed installation instructions. I'd use that as a starting point, but there may well be some architectual or setting changes that need to be tweaked to get the spice flowing.
  • This topic is deleted!

    1
    0 Votes
    1 Posts
    5 Views
    No one has replied
  • 'ip heap-size' and 'ip6 heap-size' do not work.

    2
    0 Votes
    2 Posts
    575 Views
    DerelictD
    There was an issue with heap-size that will be corrected in version 20.10.1.
  • RPKI disabled

    1
    3 Votes
    1 Posts
    483 Views
    No one has replied
  • This topic is deleted!

    1
    0 Votes
    1 Posts
    2 Views
    No one has replied
  • This topic is deleted!

    1
    0 Votes
    1 Posts
    10 Views
    No one has replied
  • This topic is deleted!

    1
    1
    0 Votes
    1 Posts
    3 Views
    No one has replied
  • This topic is deleted!

    1
    0 Votes
    1 Posts
    6 Views
    No one has replied
  • Remote syslog support

    3
    0 Votes
    3 Posts
    476 Views
    jimpJ
    The upcoming 20.10 release has IPFIX NAT logging which will fill that need for most situations.
  • TNSR with ESXI VMXNET3 - unable to load interfaces

    4
    0 Votes
    4 Posts
    803 Views
    S
    Using "BIOS" boot mode instead of "UEFI" seemed to solve the issue. Thanks for the hints. Stefano
  • Ability for IPSEC ipip tunnel interfaces to be unnumbered

    Moved
    2
    0 Votes
    2 Posts
    650 Views
    jimpJ
    Currently the only supported IPsec method is routed IPsec as described in the docs. Policy-based tunnels are something we are looking to add, but there is no ETA.
  • Cross Post : DHCP-PD

    2
    0 Votes
    2 Posts
    400 Views
    jimpJ
    At the moment there isn't support for an IPv6 DHCP client on TNSR interfaces.
  • How to read metrics from prometheus endpoint ?

    8
    1 Votes
    8 Posts
    1k Views
    jimpJ
    I had a chance to look at the data from Prometheus on TNSR and the nodes you'll be interested in to track load appear to be: _sys_vector_rate _sys_vector_rate_per_worker That's on 20.10 which will be out soon. I didn't have a 20.08 system with Prometheus handy to see if it had the same data.
  • 0 Votes
    3 Posts
    575 Views
    S
    @Derelict Thanks for reply. Did you mean NPAR(NIC Partitioning)? Could you indicate the specific name of the feature which enables that one NIC presents to the OS as 4 NICs? Or could you recommend some NICs from TNSR recommended NICs etc?
  • This topic is deleted!

    1
    0 Votes
    1 Posts
    8 Views
    No one has replied
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.