I'm curious to hear. Is snort still only single threaded on a CPU or have newer versions allowed it to run on more than one core? What I need is to make sure I have enough machine to run my WAN and about 4 VLANs.
Each would have an interface to monitor, but where I'm stuck is the rule sets... I read online where a great determining calculation is this... 1 CPU = (1000 signatures ) * (500 megabits network traffic) So my question would be....if each interface has its own rule set aside from the main download of rules. Does that factor in? If it does.....With it being a package in pfsense is there load balancing that pfsense would do for the snort package? _______________________________________________ List mailing list [email protected] http://lists.pfsense.org/mailman/listinfo/list
