• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Anyone using A2SDI-8C+-HLN4F for pfSense with 1G bandwith with IDS? Thoughts?

Scheduled Pinned Locked Moved Hardware
5 Posts 3 Posters 1.1k Views 3 Watching
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • Z Offline
    Z3r0sum
    last edited by Nov 27, 2018, 1:58 AM

    Anyone's using A2SDI-8C+-HLN4F for pfSense with IDS turned on a 1gbps internet bandwith?
    What are your thoughts.?

    A 1 Reply Last reply Dec 3, 2018, 10:18 PM Reply Quote 0
    • S Offline
      stephenw10 Netgate Administrator
      last edited by Nov 27, 2018, 4:25 PM

      That's a C3758 for reference. Any board using that is going to have very similar performance since it's an SoC.

      There are a lot of variables with Snort/Suricata. I would expect it to pass 1Gbps with a basic setup but Snort can eat a lot of resources with all the options set.
      I have never tested that CPU/board myself though.

      Steve

      Z 1 Reply Last reply Nov 27, 2018, 5:25 PM Reply Quote 0
      • Z Offline
        Z3r0sum @stephenw10
        last edited by Nov 27, 2018, 5:25 PM

        @stephenw10 said in Anyone using A2SDI-8C+-HLN4F for pfSense with 1G bandwith with IDS? Thoughts?:

        That's a C3758 for reference. Any board using that is going to have very similar performance since it's an SoC.

        There are a lot of variables with Snort/Suricata. I would expect it to pass 1Gbps with a basic setup but Snort can eat a lot of resources with all the options set.
        I have never tested that CPU/board myself though.

        Steve

        Thanks for your replies Steve. But doesnt XG-7100 1U use one of the similar CPU's (at 4 cores, while the one i listed is 8), and is touted to be one of the best Hardware Appliance for pfsense?

        1 Reply Last reply Reply Quote 0
        • S Offline
          stephenw10 Netgate Administrator
          last edited by Nov 27, 2018, 8:42 PM

          Yes, it is a C3K CPU (C3558) but not that exact one and not that board. But even if it was, as I said, Snort/Suricata can have very different throughputs depending how they're configured.

          Steve

          1 Reply Last reply Reply Quote 0
          • A Offline
            abcnew @Z3r0sum
            last edited by abcnew Dec 3, 2018, 10:23 PM Dec 3, 2018, 10:18 PM

            You can use suricata other than snort for 1gbps throughput IDS. There are no GUI setting method in current pfSense for snort to fork multi processes to monitor an interface. (200mbps per snort process from Security Onion and other snort documents.)
            From the information of a reddit post, XG-7100 is sure can make 1gbps IDS with suricata.

            I have used suricata as IDS in a C3758 barebone and used iperf2 to test the throughput of an suricata monitored gigabit interface then got 946mbps on download.

            1 Reply Last reply Reply Quote 0
            5 out of 5
            • First post
              5/5
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
              This community forum collects and processes your personal information.
              consent.not_received