Saturday, August 1, 2020

Rough CPU requirements for gigabit throughput with IPS/IDS on?

So I've been using a UniFi USG-Pro4 in conjunction with a UniFi 24 port(with 250W for PoE) switch for some time now, and while I like it for the most part, I'm not happy with how I have to do some really off-cuff things with jsons to set up multiple IPs on the WAN interface(I have a static block of IPs from my ISP), and I'm at the point now where I need to have an IPS/IDS that doesn't hamstring my throughput, and I'm not a fan of UniFi's new approach (in the new UDM) of forcing you to associate your network with a UniFi account.
So at the moment I'm looking at building a pfSense router(which solves most of my config problems), that will be able to run Snort, and be capable of at least 1Gbps throughput(using snort), for a network with only 4 users(and 2 VPN users), and 4-5 servers on the network.
As I asked in the title, I'm looking for some guidance on how powerful of a processor(without going full overkill), and to a certain extent how much RAM(though I'm guessing I shouldn't need any more than 8GB of ECC, and that's probably overkill) I need to manage that 1Gbps w/ a full featured Snort or Suricatta ruleset.



No comments:

Post a Comment