Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Snort memory usage drops by %50

    Scheduled Pinned Locked Moved IDS/IPS
    12 Posts 4 Posters 2.7k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • BBcan177B
      BBcan177 Moderator
      last edited by

      At startup, Snort will use more memory as it is configuring and loading all of its settings. Recommend also to use "AC-BNFA-NQ".

      "Experience is something you don't get until just after you need it."

      Website: http://pfBlockerNG.com
      Twitter: @BBcan177  #pfBlockerNG
      Reddit: https://www.reddit.com/r/pfBlockerNG/new/

      1 Reply Last reply Reply Quote 0
      • F
        fantasypoo
        last edited by

        @BBcan177:

        At startup, Snort will use more memory as it is configuring and loading all of its settings. Recommend also to use "AC-BNFA-NQ".

        Thanks, I prefer AC because I have the pfsense model C2758 and it has 8gb of ram.

        1 Reply Last reply Reply Quote 0
        • BBcan177B
          BBcan177 Moderator
          last edited by

          There are issues with using "AC", even if RAM is available…

          Several people have had issues and dropped down to "AC-BNFA-NQ" and never looked back :)  (Me included).  Several posts in the IDS forum.

          "Experience is something you don't get until just after you need it."

          Website: http://pfBlockerNG.com
          Twitter: @BBcan177  #pfBlockerNG
          Reddit: https://www.reddit.com/r/pfBlockerNG/new/

          1 Reply Last reply Reply Quote 0
          • F
            fantasypoo
            last edited by

            @BBcan177:

            There are issues with using "AC", even if RAM is available…

            Several people have had issues and dropped down to "AC-BNFA-NQ" and never looked back :)  (Me included).  Several posts in the IDS forum.

            thx for the tip!
            how much ram do you have ?

            1 Reply Last reply Reply Quote 0
            • BBcan177B
              BBcan177 Moderator
              last edited by

              @fantasypoo:

              @BBcan177:

              There are issues with using "AC", even if RAM is available…

              Several people have had issues and dropped down to "AC-BNFA-NQ" and never looked back :)  (Me included).  Several posts in the IDS forum.

              thx for the tip!
              how much ram do you have ?

              Several different boxes in the range of 3GB, 4GB, 8GB, 32GB…

              Even at 32GB, "AC" was causing issues, plus it takes forever to reload the Snort config when using "AC". It also caused some random Snort crashes with no particular log errors to debug... My 2cents!

              "Experience is something you don't get until just after you need it."

              Website: http://pfBlockerNG.com
              Twitter: @BBcan177  #pfBlockerNG
              Reddit: https://www.reddit.com/r/pfBlockerNG/new/

              1 Reply Last reply Reply Quote 0
              • F
                fantasypoo
                last edited by

                @fantasypoo:

                @BBcan177:

                There are issues with using "AC", even if RAM is available…

                Several people have had issues and dropped down to "AC-BNFA-NQ" and never looked back :)  (Me included).  Several posts in the IDS forum.

                thx for the tip!
                how much ram do you have ?

                https://forum.pfsense.org/index.php?topic=75216.msg410701#msg410701
                I read this forum post and the suggestion was more ram.  I have ordered another 8gb ECC ram …hopefully this will be the cure for running it in AC mode.

                1 Reply Last reply Reply Quote 0
                • bmeeksB
                  bmeeks
                  last edited by

                  No modes other than AC-BNFA or AC-BNFA-NQ are recommended.  Expect problems with AC mode.  Don't know why, but it just seems to gobble up RAM and does not really boost performance much – certainly not enough of a boost to justify the random issues it causes.

                  Bill

                  1 Reply Last reply Reply Quote 0
                  • F
                    fantasypoo
                    last edited by

                    @bmeeks:

                    No modes other than AC-BNFA or AC-BNFA-NQ are recommended.  Expect problems with AC mode.  Don't know why, but it just seems to gobble up RAM and does not really boost performance much – certainly not enough of a boost to justify the random issues it causes.

                    Bill

                    hmm.. does the same apply to Suricata ?  Default is AC

                    1 Reply Last reply Reply Quote 0
                    • D
                      doktornotor Banned
                      last edited by

                      AC-BNFA-NQ is not available in Suricata.

                      1 Reply Last reply Reply Quote 0
                      • F
                        fantasypoo
                        last edited by

                        I will upgrade to 32gb ram over the coming weeks…  I may sound like a raving lunatic but I can't stand for this "AC-BNFA-NQ"

                        1 Reply Last reply Reply Quote 0
                        • bmeeksB
                          bmeeks
                          last edited by

                          @fantasypoo:

                          hmm.. does the same apply to Suricata ?  Default is AC

                          Suricata is a completely different binary code base.  You can't really compare the two in this area.

                          Bill

                          1 Reply Last reply Reply Quote 0
                          • First post
                            Last post
                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.