Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    SG-1100 and SG-3100 throughput with IDS/IPS

    Scheduled Pinned Locked Moved Official Netgate® Hardware
    3 Posts 2 Posters 2.0k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • I
      imthenachoman
      last edited by

      Does anyone have information on the maximum throughput on these devices with IDS/IPS enabled?

      This is for my home. I am thinking of putting it between my cable modem and current router. Or, since the SG-3100 can be used as a router, I could replace my current one with it too.

      My internet speed is 200 Mbps right now so I'd need to make sure the device can maintain that throughput with IDS/IPS enabled. Ideally I'd like some room to grow in case I get faster internet later.

      1 Reply Last reply Reply Quote 0
      • stephenw10S
        stephenw10 Netgate Administrator
        last edited by

        It's difficult to give you a hard figure on that as the throughput with Snort or Suricata running can be very dependent on what rulesets you have loaded and the Detection Engine settings.
        But as a, very, rough guide I can push ~750Mbps through an SG-3100 here with Suricata running at default settings on the WAN. That's with ET Open and Snort GPL rules loaded and enabled. 1 rule files processed. 20610 rules successfully loaded. That's to a local iperf server but in a different subnet. There's a good chance that's being limited by the upstream firewall it has to route though, that is not sized for full Gigabit my WAN is far smaller.

        Steve

        I 1 Reply Last reply Reply Quote 0
        • I
          imthenachoman @stephenw10
          last edited by

          @stephenw10 Sounds like it should be fine to meet my 200 Mbps internet. I am trying pfSense on a spare computer I had. If it works I might just buy the SG-3100. Thanks!

          1 Reply Last reply Reply Quote 0
          • First post
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.