Suricata inline and limiters
It's been a while since I looked at this and searching revealed only old posts.
Is it still the true that Suricata inline (netmap) and limiters (fq_codel) are incompatible?
pfSense 2.4.5/Suricata package 5.0.2_2
bmeeks last edited by bmeeks
Yes, I'm pretty sure they are still incompatibile. I have not personally tested it lately, but several others have posted in the past with pfSense-2.4.4 that limiters and inline (
netmap) mode are incompatible. I know of no code enhancements in FreeBSD 11.3/STABLE (and hence, pfSense-2.4.5) that would change this.
I believe it would take quite a lot of work (meaning code rewrite) within the FreeBSD kernel and perhaps within the
netmapdevice driver to make limiters and
netmaplike each other. In this case, the issue is not with Suricata itself, but instead is just a consequence of how
netmaphooks into the kernel networking stack.
@bmeeks Thanks Bill. A better cable modem will reduce my buffer bloat issue ;)