HELLO_wORLD
Very Senior Member
I prepared my SBC (odroid N2+) to do some IDS (and to spare the router to do any analysis).
I got a second ethernet port (USB3), connected it to the R7800 LAN1 and enabled the port mirroring (from debug page)
It works, and installing an IDS software on the SBC listening to second ethernet port, I do see all WAN traffic.
I noticed that the router is loosing performance when doing port mirroring (IDS active or not, it is irrelevant to the problem)… Not visible with netdata or top, but doing a Speedtest from the LAN to internet is usually 950/950 Mbps for me. When port mirroring is enabled, it drops to 940/730 Mbps, showing that port mirroring as a serious impact.
This is very deceiving, and I will abandon the IDS project for now. I will need to install a small hub between internet and the WAN port of the router (before the router then) to duplicate the traffic without impacting performances.
If there is a way to do a more efficient port mirroring from command line, I am interested…
I got a second ethernet port (USB3), connected it to the R7800 LAN1 and enabled the port mirroring (from debug page)
It works, and installing an IDS software on the SBC listening to second ethernet port, I do see all WAN traffic.
I noticed that the router is loosing performance when doing port mirroring (IDS active or not, it is irrelevant to the problem)… Not visible with netdata or top, but doing a Speedtest from the LAN to internet is usually 950/950 Mbps for me. When port mirroring is enabled, it drops to 940/730 Mbps, showing that port mirroring as a serious impact.
This is very deceiving, and I will abandon the IDS project for now. I will need to install a small hub between internet and the WAN port of the router (before the router then) to duplicate the traffic without impacting performances.
If there is a way to do a more efficient port mirroring from command line, I am interested…