Owner: Emmanuel Technology Consulting
Former Sophos SG(Astaro) advocate/researcher/Silver Partner
PfSense w/Suricata, ntopng,
Other addons to follow
Owner: Emmanuel Technology Consulting
Former Sophos SG(Astaro) advocate/researcher/Silver Partner
PfSense w/Suricata, ntopng,
Other addons to follow
in a high speed streaming environment while http proxy is also highly active..no. There's simply not enough cpu available for something highly multi-threaded(http proxy) and something highly single threaded( ops aka snort) to run in a high demand situation at the same time. This is why you see the weird readings on speedtest.net with ips on. Also the atom is a multi threaded designed cpu and isn't a highly power single threaded cpu.
Thanks for the info.
I only have Firewall, IPS and AV enabled, and there are only 3 users behind this gateway. Here are my stats for the last month from the dashboard.
Maximum Minimum Average Last
CPU Usage 65.95% 2.50% 3.80% 2.58%
I assumed this box would have plenty of power for my limited needs.
Owner: Emmanuel Technology Consulting
Former Sophos SG(Astaro) advocate/researcher/Silver Partner
PfSense w/Suricata, ntopng,
Other addons to follow
Not with ips and http proxy and av on no...the atom is good for at most 30-50 megabits in best case. You really need a minimum of a pentium DC or even haswell celeron DC 2.5ghz or faster if you want to use those features with higher than 50 megabits. Do NOT go QC though as you will have further performance problems as you simply don't have enough users to properly push the utm software right now.
With the exception of the new 8 Core Rangeley and Avoton Intel Atoms.
Intel Atom C2750 - 8 Core Avoton / Rangeley BenchmarksServeTheHome – Server and Workstation Reviews
.
Owner: Emmanuel Technology Consulting
Former Sophos SG(Astaro) advocate/researcher/Silver Partner
PfSense w/Suricata, ntopng,
Other addons to follow
Not with ips and http proxy and av on no...the atom is good for at most 30-50 megabits in best case. You really need a minimum of a pentium DC or even haswell celeron DC 2.5ghz or faster if you want to use those features with higher than 50 megabits. Do NOT go QC though as you will have further performance problems as you simply don't have enough users to properly push the utm software right now.
I realize this is an older thread, but thought I'd pitch in my experience. I'm running an Atom D2550. With IPS, web filtering, AV on ... I'm getting 110+ mbps down on speedtest.net and testmy.net.
I was getting the same speeds with pfsense on the same hardware, with almost all snort rules turned on and squid http proxy filtering. And I am not maxing out the core. I think it will handle up to 150 mbps.
Anyway, just my 2 cents.
Owner: Emmanuel Technology Consulting
Former Sophos SG(Astaro) advocate/researcher/Silver Partner
PfSense w/Suricata, ntopng,
Other addons to follow