Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Suricata Kills down speed

    Scheduled Pinned Locked Moved pfSense Packages
    22 Posts 6 Posters 3.5k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M
      maverikh @Dobby_
      last edited by

      @dobby_ @jdeloach @Gertjan

      I didnt build the Protectli FW4c. Factory built it, i will change the thermal paste though.
      Im am looking up the @bmeeks recommendations for ids/ips configuration as i am new to using this aspect of the firewall and package

      Intel Celeron J3710 2.6Ghz 4-cores (just realized its only clocking in at 1.6Ghz) (40C temp)
      8GB ram (typo)
      4x Individual Intel 2.5Gbps nic's (independent cpu lanes)
      hardware encryption enabled (for OpenVPN)
      1Gbps/1Gbps internet

      standard PFSense Plus install 23.01 with:
      Suricata (using paid OINK code from snort)(inline/workers)
      OpenVPN with just 2 cellphones connected
      BandwidthD for bandwitdth usage graphs
      MiniUPNPd for 2 xbox's

      Dobby_D 1 Reply Last reply Reply Quote 0
      • Dobby_D
        Dobby_ @maverikh
        last edited by

        @maverikh

        • PowerD activated? (high adaptive)

        #~. @Dobby

        Turris Omnia - 4 Ports - 2 GB RAM / TurrisOS 7 Release (Btrfs)
        PC Engines APU4D4 - 4 Ports - 4 GB RAM / pfSense CE 2.7.2 Release (ZFS)
        PC Engines APU6B4 - 4 Ports - 4 GB RAM / pfSense+ (Plus) 24.03_1 Release (ZFS)

        M 1 Reply Last reply Reply Quote 0
        • M
          maverikh @Dobby_
          last edited by

          @dobby_
          no powerd. should i use it even though no battery ups?

          M Dobby_D 2 Replies Last reply Reply Quote 0
          • M
            maverikh @maverikh
            last edited by

            So i put artic silver on the cpu and turned on powerd (HiAdaptive). cpu temp went down 10c dashboard still says 1.6Ghz

            S 1 Reply Last reply Reply Quote 0
            • S
              SteveITS Galactic Empire @maverikh
              last edited by SteveITS

              @maverikh 2.6 is the burst/turbo. 1.6 base.

              https://ark.intel.com/content/www/us/en/ark/products/91532/intel-pentium-processor-j3710-2m-cache-up-to-2-64-ghz.html

              As noted above look at the % CPU usage while doing your test. If it’s maxed out, it’s maxed out.

              Edit: powerd will reduce the clock speed if idle. When working pfSense will show two numbers on the dashboard.

              Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
              When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
              Upvote 👍 helpful posts!

              M 1 Reply Last reply Reply Quote 0
              • M
                maverikh @SteveITS
                last edited by

                @steveits Thank you all, Correct me if im wrong with this....

                It's safe to say that if my CPU is at 7% utilization and then I loaded Suricata, and it only jumps the CPU to roughly 16% ...its not likely the cpu will speed up and therefore having some affect on internet bandwidth.

                PowerD (maximum) has no affect on CPU clock when set.
                I wanted to see if bandwidth improved directly by having the CPU run full clock speed.

                S 1 Reply Last reply Reply Quote 0
                • S
                  SteveITS Galactic Empire @maverikh
                  last edited by

                  @maverikh Then CPU isn’t your bottleneck. Are you using inline or legacy/default mode? I skimmed the above, didn’t see the NICs posted?

                  Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
                  When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
                  Upvote 👍 helpful posts!

                  M 1 Reply Last reply Reply Quote 0
                  • M
                    maverikh @SteveITS
                    last edited by

                    @steveits Inline workers.

                    Intel 2.5Gbps nic's x4 ports I think its the I225-V
                    Protectli FW4C

                    1 Reply Last reply Reply Quote 0
                    • Dobby_D
                      Dobby_ @maverikh
                      last edited by

                      @maverikh

                      no powerd. should i use it even though no battery ups?

                      If you use it (powerD high adaptive) and your internet
                      traffic goes under higher load and the CPU is not
                      scaling up (turn up to higher GHz), this will be then
                      the problem as I see it, and you may solve it by setting
                      up PowerD.

                      So i put artic silver on the cpu
                      cpu temp went down 10c dashboard

                      The most clients (buyers) of QoTom, Protectli,......
                      will do so often it first, after arriving and unpacking
                      as I have seen them reporting and also like you say
                      the temp went something between 5 C° to 10 C°
                      then down!

                      What numbers you will see at the WAN port (throughput)
                      if you are not using suricata? I mean you said it went down
                      to something around 300 MBit/s, but from how much before?

                      #~. @Dobby

                      Turris Omnia - 4 Ports - 2 GB RAM / TurrisOS 7 Release (Btrfs)
                      PC Engines APU4D4 - 4 Ports - 4 GB RAM / pfSense CE 2.7.2 Release (ZFS)
                      PC Engines APU6B4 - 4 Ports - 4 GB RAM / pfSense+ (Plus) 24.03_1 Release (ZFS)

                      M 1 Reply Last reply Reply Quote 0
                      • M
                        maverikh @Dobby_
                        last edited by

                        @dobby_ 1Gpbs down to now 500Mbps so i saw some improvement

                        Dobby_D 1 Reply Last reply Reply Quote 0
                        • Dobby_D
                          Dobby_ @maverikh
                          last edited by

                          @maverikh said in Suricata Kills down speed:

                          1Gpbs down to now 500Mbps so i saw some improvement

                          Are you using PPPoE on that internet account? If so your
                          pfSense will be nailed or pinned to one CPU core!!! If not
                          the entire WAN load will be balanced over all CPU cores
                          pending on your settings, your NIC (support it or not) and
                          also the amount and size of queues that will be able to set up. 4C / 4T = 4 queues and more queues means more transported data and for sure faster throughput comes bysite

                          #~. @Dobby

                          Turris Omnia - 4 Ports - 2 GB RAM / TurrisOS 7 Release (Btrfs)
                          PC Engines APU4D4 - 4 Ports - 4 GB RAM / pfSense CE 2.7.2 Release (ZFS)
                          PC Engines APU6B4 - 4 Ports - 4 GB RAM / pfSense+ (Plus) 24.03_1 Release (ZFS)

                          M 1 Reply Last reply Reply Quote 0
                          • M
                            maverikh @Dobby_
                            last edited by

                            @dobby_ Its fiber to the modem ONT, 1Gbps/1Gbps synchronis. not ppoe. Gateway based

                            Dobby_D 1 Reply Last reply Reply Quote 0
                            • Dobby_D
                              Dobby_ @maverikh
                              last edited by

                              @maverikh said in Suricata Kills down speed:

                              Its fiber to the modem ONT, 1Gbps/1Gbps synchronis. not ppoe. Gateway based

                              You could try out to play around with the queue amount
                              and also the size to get let call it something more out for
                              your max. throughput.

                              #~. @Dobby

                              Turris Omnia - 4 Ports - 2 GB RAM / TurrisOS 7 Release (Btrfs)
                              PC Engines APU4D4 - 4 Ports - 4 GB RAM / pfSense CE 2.7.2 Release (ZFS)
                              PC Engines APU6B4 - 4 Ports - 4 GB RAM / pfSense+ (Plus) 24.03_1 Release (ZFS)

                              M 1 Reply Last reply Reply Quote 0
                              • M
                                maverikh @Dobby_
                                last edited by

                                @dobby_ Perhaps my tunables is part of issues....

                                3a9eebce-21b7-4482-9dcf-cef2b7499b16-image.png

                                1 Reply Last reply Reply Quote 0
                                • First post
                                  Last post
                                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.