Ethernet Card Issues (Suggestions of new NIC hardware)

170 views
Skip to first unread message

Vaha

unread,
Feb 26, 2014, 12:35:21 PM2/26/14
to securit...@googlegroups.com
Hello,

I noticed that every single card we had with our hardware has been having issues since it couldn't handle the amount of traffic received.

Our server is able to last for 30 minutes and just crash (kernel) and not come back up again.

My question is to all of the users using Security Onion is to which hardware is the best one you have used in your environment that can support up to 2000 machines without crashing.

Hardware suggestions are much appreciated. If you know of any models that are Gigabit and support Ubuntu natively I would greatly appreciate it.

Thanks,

Vaha

Doug Burks

unread,
Feb 26, 2014, 1:31:41 PM2/26/14
to securit...@googlegroups.com
Hi Vaha,

Most users report good experiences with Intel NICs.

However, if you're having kernel panics, are you sure it is the NIC?

Have you run full diagnostics on your server hardware?

How much RAM do you have?
> --
> You received this message because you are subscribed to the Google Groups "security-onion" group.
> To unsubscribe from this group and stop receiving emails from it, send an email to security-onio...@googlegroups.com.
> To post to this group, send email to securit...@googlegroups.com.
> Visit this group at http://groups.google.com/group/security-onion.
> For more options, visit https://groups.google.com/groups/opt_out.



--
Doug Burks

Vaha

unread,
Feb 26, 2014, 6:35:16 PM2/26/14
to securit...@googlegroups.com
Hello Doug,

So I currently have a system that has 2 quad core CPU and 16GB of RAM. I did all of the diagnostics on the hardware and didn't receive any errors.

So I think it has to be my Ethernet card since we get about 2-3GB of traffic in less than 5 minutes.

So if you have any suggestions on an Intel model that can withstand a large amount of traffic, I would be glad to go and purchase it.

Thanks,

Vaha

Greg Williams

unread,
Feb 26, 2014, 7:22:59 PM2/26/14
to securit...@googlegroups.com
Vaha, I use Intel ET cards. I process around 700 Mbps sustained without loss.

Michal Purzynski

unread,
Feb 26, 2014, 7:59:04 PM2/26/14
to securit...@googlegroups.com
If you need something for 10Gbit than anything on the X520 chipset will
be great, like this (there are also 2 ports versions and one accepting
different optics, so choose wisely)

http://ark.intel.com/products/39773/Intel-Ethernet-Converged-Network-Adapter-X520-SR1

For the 1Gbit I had good experiences with

http://www.intel.com/content/www/us/en/network-adapters/gigabit-network-adapters/pro-1000-pt-dp.html

(which is also ridiculously cheap and you have two ports).

Doug Burks

unread,
Feb 27, 2014, 6:33:32 AM2/27/14
to securit...@googlegroups.com
On Wed, Feb 26, 2014 at 6:35 PM, Vaha <vah...@gmail.com> wrote:
> Hello Doug,
>
> So I currently have a system that has 2 quad core CPU and 16GB of RAM.

You might want to consider increasing the RAM while you're at it.

Vaha

unread,
Feb 27, 2014, 1:15:49 PM2/27/14
to securit...@googlegroups.com
Ok so here are a bit more updated specs on this machine.

Intel Xeon E5620 Two 2.40 GhZ Quad Core Processors (8 physical cores, 16 cores with Hyper-Threading)
We actually have 64GB of memory DDR3 with 1066 MHz. My mistake!

So we will have to look at a Gigabit Ethernet adapter. The Intel Pro series have reached end of life what Michael P. stated. What is their newest model with the highest level of cores?

I also want to know if we get a dual Gigabit port card, is there a possibility to use both ports as load balancers?

Thanks,

Vahidin

Michal Purzynski

unread,
Feb 27, 2014, 3:18:13 PM2/27/14
to securit...@googlegroups.com
On 2/27/14, 7:15 PM, Vaha wrote:
> Ok so here are a bit more updated specs on this machine.
>
> Intel Xeon E5620 Two 2.40 GhZ Quad Core Processors (8 physical cores, 16 cores with Hyper-Threading)
> We actually have 64GB of memory DDR3 with 1066 MHz. My mistake!
That looks so much better.
>
> So we will have to look at a Gigabit Ethernet adapter. The Intel Pro series have reached end of life what Michael P. stated. What is their newest model with the highest level of cores?
No idea, will let someone else fill in here, I only do 10Gbit on X520-SR1.
> I also want to know if we get a dual Gigabit port card, is there a possibility to use both ports as load balancers?
Well _something_ in front of the cards would need to do the load
balancing for you. Either a specialized device (like NetOptics
xDirector) or ask your network vendor.
>
> Thanks,
>
> Vahidin
>

MattH

unread,
Feb 27, 2014, 5:49:49 PM2/27/14
to securit...@googlegroups.com
Hi,

Along this line of discussion, would any PF_RING module reconfiguration/rebuild be required in order to replace an existing NIC (Broadcom on this case) with a new Intel e1000?

thanks,

Matt

Michal Purzynski

unread,
Feb 27, 2014, 6:04:35 PM2/27/14
to securit...@googlegroups.com
No, the PF_RING does not require that.
Reply all
Reply to author
Forward
0 new messages