This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

What is the best way to accelerate SNORT/IDS/IPS? It's cutting my bandwidth in half?!

I am on Gigabit FIOS symmetric.  W/O IPS/IDS/SNORT I get about 890 Mbit/s once I turn on IPS/IDS/SNORT regardless on how many rules I have there I get between 360 to 390 Mbit/s (via speedtest by Ookla...same test for 890) the range is respective from LINUX only rules to the WHOLE SHEBANG EVERYTHING ON  so in the end I am getting about half the download speed by just turning the IPS/IDS/SNORT on....what the hell?!!!  There must be a way to optimize it...I mean come on LINUX vs EVERYTHING and I only gain 30 Mbit/s?!



This thread was automatically locked due to age.
Parents
  • Hi Rick,

    what error values are reported in the IPS settings and do your logs/reports show any rule that is causing the slowdown?

    What functions of IPS do you enable? There is another thread that recommends not to use the TCP flood after setup.

    Ian

Reply
  • Hi Rick,

    what error values are reported in the IPS settings and do your logs/reports show any rule that is causing the slowdown?

    What functions of IPS do you enable? There is another thread that recommends not to use the TCP flood after setup.

    Ian

Children