Snort and system tunable net.inet.tcp.tso=0
-
I just noticed that if you set the following in the GUI the system tunable does not change to reflect that you disabled it
for snort to work well Hardware TCP Segmentation Offloading must be disabled. However the GUI seems to not change the actual net.inet.tcp.tso to 0
You have to also manually change it under system tunableables
I don't know if anyone has spotted this issue.
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.