Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Suricata, ESXi, inline, vmxnet3

    Scheduled Pinned Locked Moved IDS/IPS
    5 Posts 3 Posters 831 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • J
      justme2
      last edited by

      Any changes of opinion on this combination for ESX >= 6.5, pfSense 2.6.0 with Suricata >= 6.0.4? Any reliability issues encountered? Any performance issues?

      Thanks!

      1 Reply Last reply Reply Quote 0
      • bmeeksB
        bmeeks
        last edited by

        You should be fine with that setup. Just be sure to give your VM enough RAM. For Suricata I would start at 4 GB and perhaps go even a bit higher if you intend to run tons of enabled rules. If you have the RAM available on the host, I would suggest 8 GB for a typical Suricata setup. That would leave you a nice cushion should a little extra memory be required now and then.

        1 Reply Last reply Reply Quote 1
        • Cool_CoronaC
          Cool_Corona
          last edited by

          Your Dashboard traffic graphs stops working.

          bmeeksB 1 Reply Last reply Reply Quote 0
          • bmeeksB
            bmeeks @Cool_Corona
            last edited by

            @cool_corona said in Suricata, ESXi, inline, vmxnet3:

            Your Dashboard traffic graphs stops working.

            This should be fixed in the latest pfSense. As I recall, a patch submitted to FreeBSD upstream by the OpnSense team fixed this back in late summer of 2021. It was only a problem when using Inline IPS Mode which uses the netmap device. The problem was with the way the netmap device failed to increment certain counters.

            Cool_CoronaC 1 Reply Last reply Reply Quote 0
            • Cool_CoronaC
              Cool_Corona @bmeeks
              last edited by

              @bmeeks Its not working in 2.5.2 but I havent tested 2.6.0 yet since its unstable and lack VLAN performance.

              1 Reply Last reply Reply Quote 0
              • First post
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.