Owner: Emmanuel Technology Consulting
Former Sophos SG(Astaro) advocate/researcher/Silver Partner
PfSense w/Suricata, ntopng,
Other addons to follow
Thanks William!
I wonder what I would get out of an i7-5820K over clocked to 3.8Ghz or even 4Ghz. I suspect I'll have to give up my dreams of 1Gbps for a while. There is already one company building Snort into a consumer device (I've asked but they haven't responded on speed) so maybe some consumer friendly solutions are around the corner.
Thanks
Owner: Emmanuel Technology Consulting
Former Sophos SG(Astaro) advocate/researcher/Silver Partner
PfSense w/Suricata, ntopng,
Other addons to follow
Thanks William!
I wonder what I would get out of an i7-5820K over clocked to 3.8Ghz or even 4Ghz. I suspect I'll have to give up my dreams of 1Gbps for a while. There is already one company building Snort into a consumer device (I've asked but they haven't responded on speed) so maybe some consumer friendly solutions are around the corner.
Thanks
Owner: Emmanuel Technology Consulting
Former Sophos SG(Astaro) advocate/researcher/Silver Partner
PfSense w/Suricata, ntopng,
Other addons to follow
if you go QC you have one option IMO to wring as much speed as you can..vurtualization. Make a vm with 2 vcpus and dump all ghz, ram, and hdd into that vm and let it rip.
I have 2 vcpu and almost all Ghz dedicated to the VM already. It's really a question of how much is enough. How does the UTM Snort implementation handle multiple streams? Will it automatically instantiate new instances of Snort and would it leverage different cores intelligently? I'm ok with a single stream being limited but if in aggregate they can handle the traffic I'd be ok.
Hmm... now that I think about it my ISP will give me a couple IPs. I could run all media devices though a separate instance of UTM if needed and just pin that instance to a different set of cores. That would not be as appealing but it would be better than ripping UTM out completely.
Dan
Owner: Emmanuel Technology Consulting
Former Sophos SG(Astaro) advocate/researcher/Silver Partner
PfSense w/Suricata, ntopng,
Other addons to follow
I have 2 vcpu and almost all Ghz dedicated to the VM already. It's really a question of how much is enough. How does the UTM Snort implementation handle multiple streams? Will it automatically instantiate new instances of Snort and would it leverage different cores intelligently? I'm ok with a single stream being limited but if in aggregate they can handle the traffic I'd be ok.
Hmm... now that I think about it my ISP will give me a couple IPs. I could run all media devices though a separate instance of UTM if needed and just pin that instance to a different set of cores. That would not be as appealing but it would be better than ripping UTM out completely.
Dan
Owner: Emmanuel Technology Consulting
Former Sophos SG(Astaro) advocate/researcher/Silver Partner
PfSense w/Suricata, ntopng,
Other addons to follow