Turn on MDS Mitigation
-
Hello guys,
After I turned on MDS mitigation
As can be seen here it is already in use
But for some reason after restarting the pfSense, the function MDS mitigation stopped working.
Does anyone know what could be the cause and how it can be resolvedThanks in advance for your time!
-
@markdudov how exactly did you set it - by manual edit the tuneables?
You should just set it here. Advanced / Misc
I personally see no point to having it enabled on a firewall - but there is where you should set to what you want.
-
@johnpoz I haven't even noticed that it can be turned on from the Misc menu.
Ah, do you know where Kernel PTI can also be included?
-
@markdudov yeah again you can enable right there just above the mds if you want, again I see no point to turning these mitigations on a firewall appliance. But hey you do you..
Its like being worried about someone hitting your hand with a hammer so you wear protective gloves all the time.. But you don't even own a hammer, you never hold nails for other people to use their hammers to drive in nails.
So why should go about wearing hammer hit protection gloves?
-
@johnpoz As far as I can see in the Misc menu there is an option to disable KPTI
by default it should be on, but it is disabled for me
How can I activate it
-
It's only active on affected CPUs. Like it says there.
-
@stephenw10 Sure. And can you tell me the difference between MDs Mitigation and Kernel PTI? And whether they work together or are separate functions?
-
@markdudov are you doing a lot of hammering? These protection gloves are not needed where there is no hammer to hit your hand with..
Do you allow people to just run arbitrary code on your firewall? This is issues are related to shared hardware where users are running code directly on the hardware or something like a VM host where users can run there own vms..
These sorts of scenarios should really never be an issue on a firewall appliance.
-
Yes, they are really only of much value in a shared environment like if you are running as a VM or hosting VM in pfSense (don't do that!).