• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Snort services cpu limit

General pfSense Questions
4
12
303
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • B
    bmeeks @SpaceXTexnologiya
    last edited by Apr 11, 2025, 12:23 PM

    @SpaceXTexnologiya said in Snort services cpu limit:

    Hi,
    The snort service uses a lot of cpu and this prevents pfsense from running efficiently.
    How can I put a cpu limit on the service

    Thanks.

    The Snort binary offers no options for CPU control. Snort 2.9.x used on pfSense is a single-threaded process.

    As suggested, trim down your rule set. You don't mention what hardware you are using, but sounds like based on your description that it may not be powerful enough to run Snort with your current configuration.

    S 1 Reply Last reply Apr 11, 2025, 12:50 PM Reply Quote 0
    • S
      SpaceXTexnologiya @bmeeks
      last edited by SpaceXTexnologiya Apr 11, 2025, 12:51 PM Apr 11, 2025, 12:50 PM

      @bmeeks hi,
      thank you for reply,
      Could snort service be the cause of pfsense freezing?
      my virtualization environment is hyper-v
      pfsense running with 10 GB memory and 12 cores

      B G 2 Replies Last reply Apr 11, 2025, 1:00 PM Reply Quote 0
      • B
        bmeeks @SpaceXTexnologiya
        last edited by Apr 11, 2025, 1:00 PM

        @SpaceXTexnologiya said in Snort services cpu limit:

        Could snort service be the cause of pfsense freezing?

        I doubt Snort is the cause, but it is extraordinarily easy to test the hypothesis -- simply stop the Snort service for a day or two and see if the "freezing" still occurs. If it does not, then Snort was the likely cause. If "freezing" continues, then Snort is not the cause.

        1 Reply Last reply Reply Quote 0
        • G
          Gblenn @SpaceXTexnologiya
          last edited by 30 days ago

          @SpaceXTexnologiya said in Snort services cpu limit:

          pfsense running with 10 GB memory and 12 cores

          Wow, that is a lot of resources for pfsense! I guess you have quite a lot of traffic then?

          I'm also running virtualized but only give my firewall 8 GB RAM and 4 cores (i5 11400). I have been testing on a smaller machine with an i3 n305 and get about the same performance there (around 8 Gbit max), if I pass through the NIC's.
          I run Suricata not Snort, which probably shouldn't matter, but I run it in legacy mode...

          1 Reply Last reply Reply Quote 0
          • S
            stephenw10 Netgate Administrator
            last edited by 30 days ago

            Right probably the hvevent interrupt storm that some people are reporting. Depending on what pfSense version you're running in which hyper-v version.

            S 1 Reply Last reply 30 days ago Reply Quote 0
            • S
              SpaceXTexnologiya @stephenw10
              last edited by 30 days ago

              @stephenw10
              Which version is more stable? For Hyper-V environment

              G 1 Reply Last reply 27 days ago Reply Quote 0
              • S
                stephenw10 Netgate Administrator
                last edited by 29 days ago

                Which pfSense version? As far as know (since I don't run hyper-v) the issue affects anything built on FReeBSD 14 or newer. So that means you'd ned to go back to 2.6 to be unaffected.

                S 1 Reply Last reply 27 days ago Reply Quote 0
                • S
                  SpaceXTexnologiya @stephenw10
                  last edited by 27 days ago

                  @stephenw10 said in Snort services cpu limit:

                  Which pfSense version? As far as know (since I don't run hyper-v) the issue affects anything built on FReeBSD 14 or newer. So that means you'd ned to go back to 2.6 to be unaffected.

                  I am using pfsense version 2.7.2 on hyper-v

                  1 Reply Last reply Reply Quote 0
                  • G
                    Gblenn @SpaceXTexnologiya
                    last edited by 27 days ago

                    @SpaceXTexnologiya said in Snort services cpu limit:

                    @stephenw10
                    Which version is more stable? For Hyper-V environment

                    I guess there is the option to use another hypervisor, like Proxmox...

                    S 1 Reply Last reply 26 days ago Reply Quote 0
                    • S
                      SpaceXTexnologiya @Gblenn
                      last edited by 26 days ago

                      @Gblenn
                      currently all my environments are in hyper v so I will not be able to experiment on proxmox.
                      I can't figure out why pfsense is cutting off access but I will focus on finding out

                      thanks

                      1 Reply Last reply Reply Quote 0
                      12 out of 12
                      • First post
                        12/12
                        Last post
                      Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.