Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Suricata inline and limiters

    Scheduled Pinned Locked Moved IDS/IPS
    3 Posts 2 Posters 435 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • ?
      A Former User
      last edited by A Former User

      It's been a while since I looked at this and searching revealed only old posts.

      Is it still the true that Suricata inline (netmap) and limiters (fq_codel) are incompatible?

      pfSense 2.4.5/Suricata package 5.0.2_2

      Thanks!

      1 Reply Last reply Reply Quote 0
      • bmeeksB
        bmeeks
        last edited by bmeeks

        Yes, I'm pretty sure they are still incompatibile. I have not personally tested it lately, but several others have posted in the past with pfSense-2.4.4 that limiters and inline (netmap) mode are incompatible. I know of no code enhancements in FreeBSD 11.3/STABLE (and hence, pfSense-2.4.5) that would change this.

        I believe it would take quite a lot of work (meaning code rewrite) within the FreeBSD kernel and perhaps within the netmap device driver to make limiters and netmap like each other. In this case, the issue is not with Suricata itself, but instead is just a consequence of how netmap hooks into the kernel networking stack.

        ? 1 Reply Last reply Reply Quote 0
        • ?
          A Former User @bmeeks
          last edited by

          @bmeeks Thanks Bill. A better cable modem will reduce my buffer bloat issue ;)

          Be well!

          1 Reply Last reply Reply Quote 0
          • First post
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.